SearchFilterHost.exe

  • File Path: C:\windows\system32\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 334E8E996B23216667D9538CE40D68B5
SHA1 222224AFFA9A7B044C89ECCD2AC31BD9A5A27E36
SHA256 B77F100BB6C4F3DB1BA5FCEDE4F1EFA5D065700BCABB365266DD494C5D8A049B
SHA384 9A0629DC862702A2A4282160E9CFEEEF4DA01D8588FD32186A0DEC097C106DF234E6E1CC24A933FAB4F931500159B1AE
SHA512 F42FE5964E716E8F88047615139664711F753F8AE54B4BA772B66F8297265499BA6F69D09D6187A6DF7101C59EFC1B12BDE3564319BF0AC59216347CE25ACD6F
SSDEEP 6144:Hztew9BLoNF7lVzzdz+ZumrroiOrkR10efUK:n9BLSF7lVzzdz+ZZrFOQztf

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.17763.1098 (WinBuild.160101.0800)
  • Product Version: 7.0.17763.1098
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 41
C:\WINDOWS\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchFilterHost.exe 33
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 40
C:\Windows\system32\SearchFilterHost.exe 40
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchProtocolHost.exe 38
C:\WINDOWS\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 30
C:\Windows\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchFilterHost.exe 41
C:\Windows\SysWOW64\SearchFilterHost.exe 41
C:\Windows\SysWOW64\SearchFilterHost.exe 44
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 35
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 41
C:\Windows\SysWOW64\SearchFilterHost.exe 38
C:\Windows\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 43
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 30

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.