SearchFilterHost.exe

  • File Path: C:\Windows\system32\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 6B5D1BC8B023591838CCC5D5AA502431
SHA1 3B434B24C19BCB61F4F573368B01458F68B22E39
SHA256 39E103B2DFF413C527A75B8384119C57836852DD3A1FB1026F30E0B335732675
SHA384 2A8047356B3760A6E2818AFBEAED62B08860EB1FE196611C425B2808CC1B1F8DA88DFF13B968180159884E371FBE7287
SHA512 A2F7E3F891608CAB9458AACC32C647316E4BFC3965264187EC6BE3C7A3A3745B2E626BA37F349FFD4C719F27F50454C0C8BD396AA460760D1894226728DCBAA8
SSDEEP 3072:+Gd9UgXQ3Nph+hpjUmxXGmZU8To+TJLGjc2nOq9x91ihk6kvtfGq0ev3U5WN:f9TXyc+mxX7ZUD82nOYOrkR10efUK
IMP 25975932FE65B44EA2DD939DC008D453
PESHA1 E570DCC7849E3784141A66641807A00C5025CDE8
PE256 69A9C9B04C9D083F49AF38F1985262B65DBFE506A34310035E902B6C883189C0

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\SearchFilterHost.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002EC6579AD1E670890130000000002EC
  • Thumbprint: F7C2F2C96A328C13CDA8CDB57B715BDEA2CBD1D9
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.19041.1151 (WinBuild.160101.0800)
  • Product Version: 7.0.19041.1151
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/39e103b2dff413c527a75b8384119c57836852dd3a1fb1026f30e0b335732675/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 44
C:\WINDOWS\system32\SearchFilterHost.exe 36
C:\WINDOWS\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 40
C:\Windows\system32\SearchFilterHost.exe 41
C:\Windows\system32\SearchFilterHost.exe 40
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 46
C:\Windows\system32\SearchFilterHost.exe 44
C:\Windows\system32\SearchProtocolHost.exe 36
C:\WINDOWS\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 36
C:\Windows\system32\SearchProtocolHost.exe 30
C:\Windows\system32\SearchProtocolHost.exe 32
C:\Windows\system32\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 47
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 46
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 41
C:\Windows\SysWOW64\SearchFilterHost.exe 43
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 40
C:\Windows\SysWOW64\SearchProtocolHost.exe 47
C:\Windows\SysWOW64\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 35
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 38
C:\Windows\SysWOW64\SearchProtocolHost.exe 35

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.