What a hash is
Cryptographic hash functions are specified by NIST FIPS PUB 180-4 (Secure Hash Standard). A hash, or digest, is the fixed-length fingerprint of some data, produced by a one-way function. The same input always gives the same hash, a different input almost always gives a different one, and the input cannot be recovered from the hash. Hashes verify that a file downloaded intact, index data, and — in security — identify a known-bad file without shipping the file itself.
The algorithm determines the length, and the length is how a hash is identified on sight. MD5 is 32 hex characters, SHA-1 is 40, SHA-224 is 56, SHA-256 is 64, SHA-384 is 96 and SHA-512 is 128. This tool sorts the hex it finds into those buckets and labels each accordingly.
How to extract hashes from text
- Paste your text. A checksum file, a malware analysis report, a threat-intelligence feed, a build log — anything with hex digests in it.
- Choose which types to include. MD5, SHA-1, SHA-256 and SHA-512 are on by default; SHA-224 and SHA-384 can be added. Each type is a specific hex length, so selecting a type simply keeps that length.
- Click Extract. Only the exact known lengths are accepted, and a run of hex touching more hex on either side is rejected, so a 64-character hash inside a 128-character one is not double-counted.
- Copy or download. Copy the plain list, or download a .csv carrying each hash and its type. Lower-case output normalises everything for comparison against another list.
What comes out
- Every hash of a selected type, identified by its exact hex length — MD5, SHA-1, SHA-224, SHA-256, SHA-384 or SHA-512.
- The type label next to each one.
- Counts per type, so a checksum file's mix is visible at a glance.
- Optional lower-casing, so two lists written in different cases compare cleanly.
- A CSV export carrying each hash and its type, ready to diff against another set.
A 40-character hash is reported as SHA-1; a Git commit id has the same shape and length and will be reported the same way, because the two are genuinely indistinguishable by form.
What is supported, and what is not
Lengths matched: 32, 40, 56, 64, 96 and 128 hex characters — the digests of MD5, SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512. Only these exact lengths are accepted; a hex run of any other length is ignored, which is what keeps version strings, short identifiers and truncated values out of the results.
Boundaries are enforced. A match with another hex digit immediately before or after it is rejected, so the tool never carves a 64-character SHA-256 out of the first 64 characters of a 128-character SHA-512, and never reports a hash that is really a fragment of a longer blob.
Not identified by anything but length. The tool cannot know that a 32-character hex value is an MD5 hash rather than a random 128-bit token, or that a 40-character value is SHA-1 rather than a Git commit — nothing in the text distinguishes them. It also does not verify a hash, compute one, or reverse one; it only finds and classifies the strings.
Why the text never leaves your device
Matching runs as JavaScript in your browser. Nothing you paste is transmitted. For the full explanation of how browser-based processing works, see the security page.
This matters acutely for hashes. A list of hashes is frequently a set of indicators of compromise — the fingerprints of malware seen on a network — and pasting those into an online tool can tip off exactly the wrong party or leak the fact of an investigation. Extracting locally keeps the list on your machine.
What this tool does not do
This tool finds and classifies hashes by length. It deliberately does not:
- Verify a checksum. It does not hash a file to confirm a match — it pulls the digests out of text.
- Compute a hash. It does not turn a file or a string into a digest.
- Reverse or crack a hash. Hashes are one-way; the original input is not recoverable.
- Confirm the algorithm. A 40-character hex value is reported as SHA-1, but it could equally be a Git commit id — length alone cannot tell them apart.
- Look a hash up. No reputation or malware database is queried, because that would send the hash to a third party.
Who extracts hashes
- Security analysts — pulling the file hashes out of a malware report or a threat-intel feed to load into a blocklist or a search.
- Incident response — collecting indicators of compromise from a write-up without pasting them into an online service.
- Release engineering — extracting the checksums from a signed manifest to compare against what was actually built.
- Developers — gathering commit ids or digests scattered through logs and CI output.
- Data cleanup — separating the hashes from the surrounding text in a dump so they can be diffed against a reference list.
Hashes compared with UUIDs and other tokens
A hash is a digest of data, identified by its fixed length. A UUID is a 128-bit identifier with a distinctive 8-4-4-4-12 hyphenated shape. A MAC address is a 48-bit hardware address. All three are hex and all three turn up in the same operational logs, which is why the extractors sit together. For UUIDs use the UUID extractor; for hardware addresses, the MAC address extractor; for IPs, the IP address extractor.
If the value you are after is not one of these, the regex extractor lets you write your own pattern and runs it safely in your browser.
Frequently asked questions
How do I extract all hashes from a text file?
Paste the text above and click Extract. Every hash of a selected type is listed by length — MD5, SHA-1, SHA-256 and more — deduplicated and labelled.
How does it tell an MD5 from a SHA-256?
By length. MD5 is 32 hex characters, SHA-1 is 40, SHA-256 is 64 and SHA-512 is 128. Each length maps to exactly one algorithm, so the type is read straight from the string.
Can it crack or reverse a hash?
No. Hashes are one-way functions and the original input cannot be recovered. This tool only finds and classifies the digests in your text.
Will it mistake a Git commit for a hash?
A Git commit id is a 40-character SHA-1 and has the identical shape, so it is reported as SHA-1. Length alone cannot distinguish the two.
Are my hashes uploaded anywhere?
No. Everything runs in your browser. That matters because a hash list is often a set of indicators of compromise that should never be pasted into an online service.
Why was a hex string in my text ignored?
Only the exact lengths of real digests — 32, 40, 56, 64, 96 and 128 characters — are accepted. Any other length is skipped on purpose, which keeps tokens and version strings out.
Can it verify a file's checksum?
No. It extracts the checksums written in text; it does not hash a file to confirm a match. Use your operating system's hashing tool for that.