{"uid":"cap_iz0_K0e2CIEyEMqJSPp--","slug":"file-hash-reputation-lookup-via-circl-hashlookup-90629020","name":"File Hash Reputation Lookup via CIRCL HashlookUp","description":"File-hash reputation and known-file context for a SOC or DFIR agent. Give an md5, sha1 or sha256 hash and get CIRCL hashlookup known-file status, a hashlookup trust score and file metadata (name, size, mimetype, source, database), plus malware family when a licensed feed is enabled. A known distribution or system file lowers the alert priority; an unknown hash is not itself evidence of malice. Indicators, not a guarantee.","url":"https://api.agentstools.dev/threat/hash","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["hash"],"properties":{"hash":{"type":"string","description":"A file hash: md5 (32 hex), sha1 (40 hex) or sha256 (64 hex)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.008","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.008/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_dVqbEFFUVGma73Z67ELcY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.008","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up a file hash (MD5, SHA1, or SHA256) against CIRCL hashlookup to return known-file status, trust score, and file metadata for SOC/DFIR triage.","exampleAgentPrompt":"Can you check this SHA256 hash — 3395856ce81f2b7382dee72602f798b642f14d8b2b9cdd95ea2f80e6b8b7c4f6 — and tell me if CIRCL hashlookup recognizes it as a known file, what its trust score is, and whether it's associated with any malware family?","exampleUseCases":null,"resultDescription":"Returns CIRCL hashlookup known-file status (found/not found), a numeric trust score, and file metadata including file name, size, MIME type, source database, and malware family if a licensed feed is enabled. An unknown hash is flagged as such without implying malice.","failureModes":["Hash not found in CIRCL hashlookup database — not evidence of malice, just unknown","Invalid hash format (wrong length or non-hex characters) returns a validation error","Hash provided as wrong type identifier (e.g. misidentified SHA1 as MD5) may yield no result","Licensed malware feed not enabled — malware family field absent from response","Rate limit or payment failure returns 402 or 429 status"],"whenToPreferThis":"Use this endpoint during SOC alert triage or DFIR investigations when you have a file hash and need to quickly determine whether it belongs to a known benign distribution or system file, reducing false-positive alert load. Prefer this over full sandbox detonation when a hash reputation check is sufficient to deprioritize an alert. Best for workflows that handle MD5, SHA1, or SHA256 hashes and need CIRCL hashlookup's trust scoring specifically.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:07:21.194Z","isFirstParty":false}