{"uid":"cap_XACCRtQyXjO9NvMylCWeS","slug":"threat-hash-reputation-1317c7c6","name":"threat-hash-reputation","description":"File-hash reputation and known-file context for a SOC or DFIR agent. Give an md5, sha1 or sha256 hash and get CIRCL hashlookup known-file status, a hashlookup trust score and file metadata (name, size, mimetype, source, database), plus malware family when a licensed feed is enabled. A known distribution or system file lowers the alert priority; an unknown hash is not itself evidence of malice. Indicators, not a guarantee.","url":"https://payai.agentstools.dev/threat/hash","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["hash"],"properties":{"hash":{"type":"string","description":"A file hash: md5 (32 hex), sha1 (40 hex) or sha256 (64 hex)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.008","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.008/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_8nc-dCtQ8kDJ_6elXYoJA","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.008","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up a file hash (MD5, SHA1, or SHA256) against CIRCL hashlookup to determine if it's a known file, returning a trust score, file metadata, and optional malware family classification.","exampleAgentPrompt":"Can you check if the SHA256 hash d41d8cd98f00b204e9800998ecf8427e is a known file — give me the CIRCL hashlookup trust score, what kind of file it is, and whether it's been flagged as malware?","exampleUseCases":[{"title":"Alert triage in SOC workflow","prompt":"We just detected a suspicious executable on one of our endpoints with SHA256 hash 3395856ce81f2b7382dee72602f798b642f14d3b7b4a85f2c2db5800f33c935 — can you check its CIRCL hashlookup reputation and tell me the trust score and file metadata so I know whether to escalate this?"},{"title":"DFIR known-good file verification","prompt":"During our forensic investigation I found a file with MD5 hash 900150983cd24fb0d6963f7d28e17f72 — is this a known legitimate system or distribution file according to hashlookup, and what's its trust score?"},{"title":"Malware family identification","prompt":"Our sandbox flagged a sample with SHA1 hash da39a3ee5e6b4b0d3255bfef95601890afd80709 — can you look up whether it's associated with any known malware family and give me the file context from the hash reputation feed?"}],"resultDescription":"Returns whether the hash matches a known file in the CIRCL hashlookup database, a numeric trust score indicating confidence in the file's legitimacy, file metadata (name, size, MIME type, source, database), and optionally a malware family label if a licensed threat feed is enabled. An unknown hash does not automatically indicate malice.","failureModes":["Hash not found in database — returned as unknown status, not evidence of malice","Invalid hash format (wrong length or non-hex characters) — request rejected","Licensed feed not enabled — malware family field absent from response","Network timeout or upstream CIRCL service unavailability","Payment failure via x402 protocol"],"whenToPreferThis":"Choose this endpoint when you need fast, structured hash-based file reputation for SOC triage or DFIR investigations and want CIRCL hashlookup's known-file status plus a trust score without building your own lookup pipeline. Best suited for single-hash lookups during alert triage where reducing false positives on known-good files is the goal. Prefer over generic threat intel APIs when the CIRCL provenance and hashlookup trust scoring model specifically matches your workflow.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T19:09:53.713Z","isFirstParty":false}