Search Hash
search_hashEverything ThreatFox knows about one file hash (md5 / sha1 / sha256), across BOTH relations it stores hashes in — they are different facts and a caller with a hash in hand rarely knows which one they have. (1) sample_to_c2: the hash is a malware SAMPLE, and ThreatFox returns the botnet C&C servers that sample talks to (this is what abuse.ch's own search_hash query answers, and only this). (2) hash_listed_as_ioc: the hash is itself published as an indicator — threat_type "payload" — in which case the row IS the answer. matched_relation says which one fired, or is null when neither did. AN EMPTY RESULT IS A REAL ANSWER HERE, not a failure: ThreatFox is a C&C-tracking feed, not a sample database — most hashes on any malware site are in neither relation. It also expires every IOC older than six months, so a hash from an old report can legitimately return nothing today. For sample metadata (file type, size, signature, YARA) use the malwarebazaar pack, which is the same vendor and indexes every sample.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| hash | Yes | md5 (32 hex), sha1 (40 hex) or sha256 (64 hex). Anything else is rejected upstream as illegl_hash [sic] rather than answered empty. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | Yes | Number of results returned | |
| query | Yes | The query type sent (search_hash) | |
| status | Yes | Query status (ok, no_result, or null) | |
| results | Yes | IOCs associated with the file hash | |
| matched_relation | No | WHICH of ThreatFox's two hash relations answered. "sample_to_c2": the hash is a malware sample and the rows are the C&C servers it talks to. "hash_listed_as_ioc": the hash is itself published as an indicator (threat_type "payload") and the row IS the answer. null: neither matched - both were searched, see searched_relations. | |
| searched_relations | No | Present only when nothing matched: the relations that WERE searched, so an empty answer cannot be mistaken for a partial lookup. |