Hash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
Paste a hash on the left.
How it works
A digest is a fixed-length number. It carries no header, no label and no record of what produced it, which means identification is inference from shape — and the honest output is a list, not an answer.
Length narrows; it rarely decides
Thirty-two hex digits is MD5. It is also NTLM, MD4, and half an LM hash. Those are the same 128 bits and nothing inside the value separates them — only knowing where it came from does. A hash pulled from a domain controller dump is NTLM; the same string in a file manifest is not. So every candidate at a given length is listed, with the most frequent marked likely on grounds of frequency rather than evidence.
Some hashes do name themselves
A modular-crypt string says what it is in the prefix: $2b$ is bcrypt, $argon2id$ is
Argon2, $6$ is sha512crypt, $y$ is yescrypt. A MySQL 4.1 hash is marked by a leading
asterisk. These come back as a single answer because they were read rather than inferred, and bcrypt's cost factor
sits right there in the string.
Nothing is looked up
No rainbow table, no cracking, no outbound request. Pasting a hash here does not disclose it to anyone — which is the point, because a hash taken from an incident is frequently the most sensitive value an analyst is holding.
Example
900150983cd24fb0d6963f7d28e17f72 returns MD5, NTLM, MD4 and LM — all four, because all four fit.
$2b$12$… returns bcrypt alone, with the cost factor of 12 read straight out of the string.
Frequently asked questions
Why does it list several algorithms instead of telling me which one?
Because a bare digest does not contain the answer. A 32-digit hex string is equally consistent with MD5, NTLM, MD4 and half of an LM hash, and nothing in the string separates them — only knowing where it came from does. Naming one would be a guess presented as a finding, so all of them are listed with MD5 marked as the likeliest by frequency rather than by evidence.
What can it identify definitively?
Anything that names itself. A modular-crypt string carries its algorithm in the prefix — $2b$ is bcrypt, $argon2id$ is Argon2, $6$ is sha512crypt — and a MySQL 4.1 hash is marked by a leading asterisk. Those are read, not inferred, which is why they come back as a single answer.
Can it tell an NTLM hash from an MD5?
No, and neither can anything else looking only at the value. NTLM is MD4 over a UTF-16 password; the output is 128 bits of hex exactly like MD5. Context settles it — a hash pulled from a domain controller dump is NTLM, one from a file manifest is not.
Does it crack the hash?
No. There is no lookup, no rainbow table and no outbound request of any kind. Pasting a hash here does not disclose it to anyone, which is deliberate: hashes taken from an incident are often the most sensitive thing an analyst is holding.
What about Base64 digests?
Recognised by decoded byte count — 32 bytes is SHA-256's digest size, 20 is SHA-1's. It is weaker evidence than hex length, so those candidates are never marked likely: plenty of 32-byte values that are not digests encode to the same shape.
Related tools
Hash Generator
Produce SHA-1, SHA-256, SHA-384 and SHA-512 digests of text or a file.
LocalIOC Normalizer
Standardise a mixed indicator list into one consistent format.
LocalCVSS Calculator
Build or decode a CVSS v3.1 vector and see which metric drives the score.
LocalSRI Hash Generator
Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.
LocalCertificate Fingerprint Calculator
Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.
LocalSSH Public Key Inspector
Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.
LocalFrom the intelligence desk
- Vulnerability Ajax.NET Professional Insecure Deserialization (CVE-2021-23758)
- Vulnerability Dolibarr ERP/CRM Vulnerability (CVE-2026-89013)
- Vulnerability Flowise Code Injection (CVE-2026-69255)
- Vulnerability knowns Path Traversal (CVE-2026-86538)