TOOLS / HASH REPUTATION
Hash Reputation Checker
Paste an MD5, SHA-1, or SHA-256 hash. Or drop a file (we hash it locally — never uploaded). Cross-references MalwareBazaar and VirusTotal feeds.
Or (max 50 MB, hashed locally in your browser):
What it does
When you encounter an unknown executable, the fastest triage step is hash reputation: compute its cryptographic fingerprint and check threat-intel feeds for prior submissions. Our checker queries MalwareBazaar (abuse.ch’s curated malicious-sample database) and VirusTotal, returning the aggregated verdict plus per-source details. If you drop a file, we compute SHA-256 locally in your browser via WebCrypto — only the hash is transmitted, never the file itself.
How to use it
- Paste a hash (MD5 = 32 chars, SHA-1 = 40 chars, SHA-256 = 64 chars) OR drop a file (we hash it locally).
- Results: detection ratio from VirusTotal (e.g. 66/75), malware family from MalwareBazaar.
- For known-malicious samples: review tags (e.g. "stealer", "trojan") and first-seen date to gauge campaign age.
- Cross-reference with our news posts mentioning the family for IOC packs and YARA rules.
Common use cases
Frequently asked questions
Is my file uploaded when I drop it? +
Why does VirusTotal show "not_in_database"? +
What does the detection ratio mean? +
Which hash type is most reliable? +
What’s the rate limit? +
Related tools
Related coverage on Ciphers Security
- YARA-X 1.16.0: Faster Scans, Panic Fixes, and Neovim LSP Support
- LummaC2 Infostealer Targets US Critical Infrastructure: CISA-FBI Advisory AA25-141B and DOJ Domain Seizures
- MacSync Stealer: Hackers Abuse Google Ads and Claude.ai Chats to Push Mac Malware
- JDownloader Site Hacked, Installers Swapped with Python RAT Malware
- Operation HookedWing: 4-Year Phishing Campaign Hits 500+ Organizations Across Aviation, Energy, and Logistics
Free for everyone, no signup required. Tool runs at /tools/hash-reputation/ — bookmark or share.