SearchFilterHost.exe

  • File Path: C:\WINDOWS\SysWOW64\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 585A835BEAC7247DAE4846B5DCA8AD02
SHA1 E18E3D8E99E7E1BCC0D9A99A42120925F4ED3923
SHA256 96A3D84C4EC4F3EF5BAC95E8941023B1CFF248B9E030841D60B23AE476B48D4F
SHA384 B49855E41880E36B479847E3C22F4B30AB22A2ADDFD47D0AABBCBEA9868E23D98AA08355A8C4B46B67316EDA537B3CE9
SHA512 BC3F7CA3445B35C8E94AA79A00863F780BA7D58AAE01105697E4066DB65905D8C7C79E35C7C9AAB325F641DB85EEFE8EF0A63897E195E5CD88B7ED78368F2C03
SSDEEP 3072:/J4sBhwlpSduuDBGuWfZjgt/0Fkf7GJWuMhvYtpf1ihk6kvtfGq0ev3U5WNl:1qOBGuYkKIHvYtArkR10efUK
IMP 091469956D43DF898A2647F0EF267A9F
PESHA1 22BABDD69264F38F6B2F5B587BC223F0AAAB561F
PE256 6356B29C240DB38AF1D04FD6473D264247182E5A9B32F4374B66E7B28E9FC5E2

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\System32\wow64.dll
C:\WINDOWS\System32\wow64base.dll
C:\WINDOWS\System32\wow64con.dll
C:\WINDOWS\System32\wow64cpu.dll
C:\WINDOWS\System32\wow64win.dll
C:\WINDOWS\SysWOW64\SearchFilterHost.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.22000.282 (WinBuild.160101.0800)
  • Product Version: 7.0.22000.282
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/96a3d84c4ec4f3ef5bac95e8941023b1cff248b9e030841d60b23ae476b48d4f/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 44
C:\WINDOWS\system32\SearchFilterHost.exe 43
C:\WINDOWS\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchFilterHost.exe 47
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 47
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 46
C:\Windows\system32\SearchFilterHost.exe 49
C:\Windows\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchProtocolHost.exe 30
C:\WINDOWS\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 49
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 44
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 44
C:\Windows\SysWOW64\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 41
C:\Windows\SysWOW64\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 30
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 27
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 32

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.