SearchFilterHost.exe

  • File Path: C:\Windows\SysWOW64\SearchFilterHost.exe
  • Description: Microsoft Windows Search Filter Host

Hashes

Type Hash
MD5 98CAC0FEB32500C7CC15B6FE83F6068D
SHA1 04E8650294E3701EE648AEF55902D41F907FD40E
SHA256 25A3403A8238DB8F6FD4B6DE4113334007707F08440C7D45FBDD58747AC5835B
SHA384 D05A6122D8D3C6A79BAD09E5E0E66E5A0758379C968896B230B66C29147E11CEEAE07D83CE397230F35BE0F161CDE298
SHA512 E5623E7B32899BE42ECF268180FA86C8BB02F8DD1ABE366F4905F7C0292E20899A064D606FD234D70EB00A9736822289825AE41C0EFD23F6AD3B495B10F39AE4
SSDEEP 3072:hN9okk47++EOGECRV3tGCVLtg1ihk6kvtfGq0ev3U5WNq4:Vozb+EpECr9GCVLTrkR10efUKq

Runtime Data

Child Processes:

conhost.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SearchFilterHost.exe
  • Product Name: Windows Search
  • Company Name: Microsoft Corporation
  • File Version: 7.0.14393.3564 (rs1_release.200303-1942)
  • Product Version: 7.0.14393.3564
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\SearchFilterHost.exe 50
C:\WINDOWS\system32\SearchFilterHost.exe 44
C:\WINDOWS\system32\SearchFilterHost.exe 47
C:\Windows\system32\SearchFilterHost.exe 49
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 46
C:\Windows\system32\SearchFilterHost.exe 47
C:\Windows\system32\SearchFilterHost.exe 43
C:\Windows\system32\SearchFilterHost.exe 50
C:\Windows\system32\SearchProtocolHost.exe 35
C:\WINDOWS\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 38
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\system32\SearchProtocolHost.exe 33
C:\Windows\SysWOW64\SearchFilterHost.exe 49
C:\Windows\SysWOW64\SearchFilterHost.exe 47
C:\Windows\SysWOW64\SearchFilterHost.exe 50
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 46
C:\Windows\SysWOW64\SearchFilterHost.exe 44
C:\Windows\SysWOW64\SearchFilterHost.exe 49
C:\WINDOWS\SysWOW64\SearchFilterHost.exe 50
C:\Windows\SysWOW64\SearchFilterHost.exe 44
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 29
C:\Windows\SysWOW64\SearchProtocolHost.exe 36
C:\Windows\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 36
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 33
C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 35
C:\Windows\SysWOW64\SearchProtocolHost.exe 32
C:\Windows\SysWOW64\SearchProtocolHost.exe 27
C:\Windows\SysWOW64\SearchProtocolHost.exe 32

Possible Misuse

The following table contains possible examples of SearchFilterHost.exe being misused. While SearchFilterHost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_apt_winnti_mal_hk_jan20.yml Image\|endswith: '\SearchFilterHost.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.