SearchFilterHost.exe

  • File Path: C:\Windows\system32\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 32070FD581B3C13740432169F764F066
SHA1 0721C333FEDD293255B3324C64E5354AF3AE4A20
SHA256 AC1295DEBAF51D3562705376EEF6E8AC74DCD93DF53D30F5ECEACACBBC45C5F2
SHA384 17F51E5F165B583A3A51749E24FE348B9AA95C40D3FBBC3EB6A139E659D3F2CBC914FB03CAB3D177C0ACDAD6AD232F16
SHA512 DFD426FE196102C67903E4C63A8A33F378B7EA25FADCDFC18FC81719E109FBBDD901E1C09CC54C65F164F0FD5E172622FF519614A45BD9D9119A9DAB0A087EF9
SSDEEP 6144:G2YkMO2AEXE6h1BmnCUKGswLrkR10efUK:LYkMPAEVLnUKJwLQztf

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.14393.3564 (rs1_release.200303-1942)
  • Product Version: 7.0.14393.3564
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 43
C:\WINDOWS\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchFilterHost.exe 33
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchProtocolHost.exe 35
C:\WINDOWS\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchFilterHost.exe 38
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchFilterHost.exe 49
C:\Windows\SysWOW64\SearchFilterHost.exe 50
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 29
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 29
C:\Windows\SysWOW64\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchProtocolHost.exe 33

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.