SearchFilterHost.exe

  • File Path: C:\Windows\system32\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 1B3706231F1003B03717691C5AFCD361
SHA1 7CDD324302C3E568CDD1E187E1EC51CEFA2662DF
SHA256 FFBCF5F709E1E017EAC64AF5C9E232140FCA2D1A02A64C1FFFD965B1E5AB842F
SHA384 A0144EB7EB9555E9DE39FA8AEE6296D7611B00BC0416F4361729BFD88BC9492774928507E05B579CC1258ED72E699B5F
SHA512 D3DC86424FF4C047DA73B3A8C04D132582930DFDC2C746961CBDC46E7F1BFDA2294D82719F8DF1003F667C12BCA7805F40F72F3A8809E39BD10DDE42121887B0
SSDEEP 3072:TsZBSJaS2JnRUk7JlsIXO/aa+l+sg3JCG32sVPQp7d1ihk6kvtfGq0ev3U5WN:SBiaS2V/lxXiaPK2sVWorkR10efUK
IMP 25975932FE65B44EA2DD939DC008D453
PESHA1 9E4A389221505BC81BA68A73EDD598AEEBB5A826
PE256 79E470C9A9CAC5480D26595E047D79BD7F2D4C1115D73A4B7622A22EFE180069

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\SearchFilterHost.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.19041.610 (WinBuild.160101.0800)
  • Product Version: 7.0.19041.610
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/ffbcf5f709e1e017eac64af5c9e232140fca2d1a02a64c1fffd965b1e5ab842f/detection

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 54
C:\Windows\system32\SearchFilterHost.exe 55
C:\Windows\system32\SearchFilterHost.exe 46
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchProtocolHost.exe 36
C:\WINDOWS\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 27
C:\Windows\system32\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchFilterHost.exe 36
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 50
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 41
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\Windows\SysWOW64\SearchProtocolHost.exe 41
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 30

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.