CIRCL hashlookup (hashlookup.circl.lu)
CIRCL hashlookup is a public API for looking up file hashes in known-file databases. It includes the NSRL Reference Data Set (RDS) and several other data sources. The service is available through an HTTP REST API, which is documented using an OpenAPI specification. It is free to use and provided on a best-effort basis.
Sources included in CIRCL hashlookup
- Common Windows 10 and Windows 11 builds (French, Dutch, German, UK, and US)
- NIST NSRL - All RDS hash sets, including current, modern, Android, iOS, and legacy sets, with SHA-256 mappings
- Ubuntu distribution packages
- CentOS core operating system distribution
- Fedora Project EPEL repository
- Kali Linux distribution packages
- openSUSE distribution packages
- OpenBSD binary tar.gz archives
- CDNJS
- Snap public repository
Is this a database of malicious or non-malicious file hashes?
The CIRCL hashlookup service only provides details about known files that appear in one or more of its source databases. These details provide context for file hashes encountered during investigations or digital forensic analysis. A match does not, by itself, indicate whether a file is malicious.
hashlookup:trust
A trust level is included in every hashlookup response in the hashlookup:trust field.
The trust level ranges from 0 to 100. A value of 50 means that the service has no opinion about the file. A value below 50 indicates less confidence that the file is legitimate. A value above 50 indicates that the file appears in multiple sources and is therefore considered more trustworthy.
API Usage
Get information about the hash lookup database (via ReST)
curl -X 'GET' \
'https://hashlookup.circl.lu/info' \
-H 'accept: application/json'
|
|
Perform an MD5 hash lookup
curl -X 'GET' \
'https://hashlookup.circl.lu/lookup/md5/8ED4B4ED952526D89899E723F3488DE4' \
-H 'accept: application/json'
|
|
Perform a SHA-1 hash lookup
curl -X 'GET' 'https://hashlookup.circl.lu/lookup/sha1/FFFFFDAC1B1B4C513896C805C2C698D9688BE69F' -H 'accept: application/json' | jq .
|
|
Perform a SHA-256 hash lookup
curl -s -X 'GET' 'https://hashlookup.circl.lu/lookup/sha256/301c9ec7a9aadee4d745e8fd4fa659dafbbcc6b75b9ff491d14cbbdd840814e9' -H 'accept: application/json' | jq
|
|
Bulk search of MD5 hashes
curl -X 'POST' 'https://hashlookup.circl.lu/bulk/md5' -H "Content-Type: application/json" -d "{\"hashes\": [\"6E2F8616A01725DCB37BED0A2495AEB2\", \"8ED4B4ED952526D89899E723F3488DE4\", \"344428FA4BA313712E4CA9B16D089AC4\"]}" | jq .
|
|
Bulk search of SHA-1 hashes
curl -X 'POST' 'https://hashlookup.circl.lu/bulk/sha1' -H "Content-Type: application/json" -d "{\"hashes\": [\"FFFFFDAC1B1B4C513896C805C2C698D9688BE69F\", \"FFFFFF4DB8282D002893A9BAF00E9E9D4BA45E65\", \"FFFFFE4C92E3F7282C7502F1734B243FA52326FB\"]}" | jq .
|
|
API and HTTP return codes
| HTTP return code | Description and Interpretation |
|---|---|
| 200 | The requested hash is present in at least one database. |
| 404 | The requested hash is not present in any database. |
| 400 | The supplied hash is incorrectly formatted. |
Querying the hashlookup database via DNS
The domain to query is <query>.dns.hashlookup.circl.lu. The query can be info or an MD5 or SHA-1 value.
Information about the hashlookup database
dig +short -t TXT info.dns.hashlookup.circl.lu | jq -r . | jq .
|
|
Query a hash
dig +short -t TXT 931606baaa7a2b4ef61198406f8fc3f4.dns.hashlookup.circl.lu | jq -r . | jq .
|
|
Sample use-cases
How can I quickly check a set of files in a local directory?
sha1sum * | cut -f1 -d" " | parallel 'curl -s https://hashlookup.circl.lu/lookup/sha1/{}' | jq .
Negative results (hashes that do not exist in the database) can be excluded with the -f option in curl.
sha1sum * | cut -f1 -d" " | parallel 'curl -f -s https://hashlookup.circl.lu/lookup/sha1/{}' | jq .
Querying hashlookup without online queries
If you do not want to send your lookup queries to CIRCL, you can download and query the hashlookup Bloom filter locally.
A Bloom filter (a compact representation of the dataset) containing all SHA-1 values known to hashlookup is available at https://cra.circl.lu/hashlookup/hashlookup-full.bloom (~700 MB). It uses the format supported by the DCSO bloom library and CLI and is updated monthly.
To use the Bloom filter locally, first install the DCSO bloom CLI, and then run:
find /usr/bin/ -type f -print0 | xargs -0 sha1sum | awk '{ print $1 }' | tr a-f A-F | bloom c /home/adulau/hashlookup-full.bloom
The Bloom filter does not contain metadata; it contains only the SHA-1 hash values stored in CIRCL hashlookup. You can inspect the Bloom filter file with the bloom CLI:
adulau@kolmogorov ~/hashlookup $ bloom s hashlookup-full.bloom
File: /home/adulau/hashlookup/hashlookup-full.bloom
Capacity: 296893697
Elements present: 296890922
FP probability: 1.00e-04
Bits: 5691486835
Hash functions: 14
The hashlookup forensic analyser supports the Bloom filter and can also be used locally instead of sending online queries.
python3 bin/hashlookup-analyser.py --bloomfilter /home/adulau/hashlookup/hashlookup-full.bloom --include-stats -d /bin
Libraries and software for using CIRCL hashlookup
- PyHashlookup is a Python client for querying CIRCL hashlookup.
- TheHive Project’s Cortex Analyzers includes a pull request to integrate hashlookup with Cortex Analyzers.
- The MISP hashlookup expansion module is a MISP module for looking up hashes and expanding them with results from hashlookup.
- Munin - Online Hash Checker for VirusTotal and Other Services supports hashlookup.
- hashlookup-forensic-analyser analyses a forensic target, such as a directory, and reports which files are found or not found in the public CIRCL hashlookup service. This can help digital forensic investigators determine the context and origin of files during an investigation.
- An R package is also available for querying hashlookup.