SearchFilterHost.exe

  • File Path: C:\WINDOWS\system32\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 2296B4F9F71EFB1FCC195C85B8EA3ED9
SHA1 AA0CC5CA1AA0AC8AA5C695BACB35F31B629FFAC4
SHA256 1584A43CE318552E1191E3B550ECEB1B8E291C6D5444E72E1FC71636A0F800C9
SHA384 D96594AD864AA7F226E0AF9A56514FC3134D8C41CCF2327352FB6C47F1DEA3991323465E922D606262588A56B751F407
SHA512 4605520FD6C9B647AC147A68409A78A10CD56AE2DEDDD391A15B2F9D06CD3096BD6CC238F971FC562073B1CC6E99C9F69AF319F25A2ADEDE96A93E8493F4D1A9
SSDEEP 3072:0mF0F+skOPzY6iEu0ow8lzd+cRAjgY/3wZgDmrBrBu/KS1ihk6kvtfGq0ev3U5WN:HaRY6mPw8l5YbmrB1ysrkR10efUK

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.18362.719 (WinBuild.160101.0800)
  • Product Version: 7.0.18362.719
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 52
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchProtocolHost.exe 33
C:\WINDOWS\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchFilterHost.exe 41
C:\Windows\SysWOW64\SearchFilterHost.exe 44
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 47
C:\Windows\SysWOW64\SearchFilterHost.exe 50
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 49
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 41
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 33

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.