SearchFilterHost.exe

  • File Path: C:\windows\SysWOW64\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 09C9EB6892E603CD4265920E5A29F7CD
SHA1 6884B7744572DC42301CF23EF36C3945DEB33701
SHA256 BFEB65FEAFE356A44F6CC24D1962317C772ABC58A847A200F93C5DB69C93E98B
SHA384 BD3C8EFC23081BDE652918B6894018E97C23D7646E5CF9EBE943F94BF901449435C384C2239CBAA7D2E3A740F16BB373
SHA512 FCA6E6BD3B4A3B2CE3C7BAC569B0D48EF4FBBB6879A3FBDF8ED5D2C9DFCD37D7EFFA4A113A47BE5FB82C19E7C1DCFBE05C9A1806588AD1CC5125F0EDE6289504
SSDEEP 6144:coazi+tA/bnO7ttZnrdwGrkR10efUKVyg:coYiCADnmZdwGQztfjz

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.17763.1098 (WinBuild.160101.0800)
  • Product Version: 7.0.17763.1098
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 36
C:\WINDOWS\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 35
C:\Windows\system32\SearchFilterHost.exe 35
C:\Windows\system32\SearchFilterHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 32
C:\WINDOWS\system32\SearchProtocolHost.exe 36
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 49
C:\Windows\SysWOW64\SearchFilterHost.exe 50
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 29
C:\Windows\SysWOW64\SearchProtocolHost.exe 33

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.