Paste a file hash to get a complete threat report with AV verdicts, timeline, behavior, and IOC context.
Nothing searched yet

File Hash lookup

A file hash is the densest starting point on the platform. One value resolves to antivirus verdicts, sandbox behaviour, every network indicator the sample reached for, and the attacker techniques that behaviour maps to.

What you can paste

These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.

How to run one
  1. 1Paste the file hash into the box above. The type is already set to File Hash on this page.
  2. 2Press Analyze. If the indicator is new to the platform it is queued for enrichment, and the page holds a progress view while that runs rather than telling you to come back later.
  3. 3Read the report top-down. The verdict is the headline; the sections below it are the evidence, and the evidence is the part worth your time.
  4. 4Pivot. Almost every value in the report is itself searchable, which is how one indicator becomes an investigation.
Where to go next
  • Search any extracted IP, domain or URL to widen the picture
  • Open the cross-reference to see every sample sharing that infrastructure
  • Take the ATT&CK techniques to the attribution view for candidate actors
What comes back, and how to read it

These are the sections of the report, in the order you will meet them.

  1. 01Verdict and Detection Ratio

    The headline call, and the fraction of engines behind it. Read the ratio, not just the verdict: 2/70 and 58/70 are both 'detected' and mean very different things.

  2. 02Engine Consensus

    Which engines flagged the sample and what each one named it. Detection names are where a family label comes from, and disagreement between engines is itself a signal worth noting.

  3. 03Sandbox verdicts

    What the sample did when it was run, rather than what it looks like on disk. Behaviour survives repacking; a static signature often does not.

  4. 04Network / IOCs

    The IPs, domains and URLs extracted from the sample. This is the section you pivot from -- each entry is a search of its own, and usually the next step.

  5. 05MITRE Techniques

    Observed behaviour expressed as ATT&CK techniques, which is what lets you compare this sample to known actors and to your own detection coverage.

  6. 06Data Sources

    Which sources contributed, so you can weigh a thin result against a corroborated one. A single-source verdict is a lead, not a conclusion.