SearchFilterHost.exe

  • File Path: C:\Windows\system32\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 673511D54A34319446EAD0B820D083A6
SHA1 C36BA6DB46DD7EB6F90B83B9ABF4D28CA99BFDFB
SHA256 3596CE0D573803E261B0186D986842CB3CA80D40B65392310D13A7557F71C0A5
SHA384 0564E35F5E8D54F8E02532AB5E978ADB807FB051E984D2A9AFF41909BF87900EB1C9E45C03050057AF62AA34E84678C8
SHA512 AD260ECE4D32370A7FAA99973C48B2CE596A39CBACF34EF5DFED752C6F0FA589CE3951F7D0450A4FCFD9E66FA96E16C18F50EAAFE176D65F52E63DAC668F778C
SSDEEP 6144:SKbiiKNIy0CXzBNtd2sVi9AUrkR10efUK:SA1KNIytXzBNtTVi9AUQztf

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\SearchFilterHost.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.19041.329 (WinBuild.160101.0800)
  • Product Version: 7.0.19041.329
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 54
C:\WINDOWS\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 38
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 63
C:\Windows\system32\SearchFilterHost.exe 35
C:\Windows\system32\SearchFilterHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 35
C:\WINDOWS\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchFilterHost.exe 38
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 40
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 40
C:\Windows\SysWOW64\SearchFilterHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\Windows\SysWOW64\SearchProtocolHost.exe 36
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 29
C:\Windows\SysWOW64\SearchProtocolHost.exe 30
C:\Windows\SysWOW64\SearchProtocolHost.exe 29

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.