Extract MD5, SHA-1 and SHA-256 Hashes From Text

A hash is a fixed-length run of hex, and its length is what names it: 32 for MD5, 40 for SHA-1, 64 for SHA-256, 128 for SHA-512. Paste text below to pull them out, each one identified by type. Only the exact known lengths are accepted and anything embedded in a longer hex blob is rejected, so colour codes and half-UUIDs do not leak into the list.

What a hash is

Cryptographic hash functions are specified by NIST FIPS PUB 180-4 (Secure Hash Standard). A hash, or digest, is the fixed-length fingerprint of some data, produced by a one-way function. The same input always gives the same hash, a different input almost always gives a different one, and the input cannot be recovered from the hash. Hashes verify that a file downloaded intact, index data, and — in security — identify a known-bad file without shipping the file itself.

The algorithm determines the length, and the length is how a hash is identified on sight. MD5 is 32 hex characters, SHA-1 is 40, SHA-224 is 56, SHA-256 is 64, SHA-384 is 96 and SHA-512 is 128. This tool sorts the hex it finds into those buckets and labels each accordingly.

How to extract hashes from text

  1. Paste your text. A checksum file, a malware analysis report, a threat-intelligence feed, a build log — anything with hex digests in it.
  2. Choose which types to include. MD5, SHA-1, SHA-256 and SHA-512 are on by default; SHA-224 and SHA-384 can be added. Each type is a specific hex length, so selecting a type simply keeps that length.
  3. Click Extract. Only the exact known lengths are accepted, and a run of hex touching more hex on either side is rejected, so a 64-character hash inside a 128-character one is not double-counted.
  4. Copy or download. Copy the plain list, or download a .csv carrying each hash and its type. Lower-case output normalises everything for comparison against another list.

What comes out

A 40-character hash is reported as SHA-1; a Git commit id has the same shape and length and will be reported the same way, because the two are genuinely indistinguishable by form.

What is supported, and what is not

Lengths matched: 32, 40, 56, 64, 96 and 128 hex characters — the digests of MD5, SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512. Only these exact lengths are accepted; a hex run of any other length is ignored, which is what keeps version strings, short identifiers and truncated values out of the results.

Boundaries are enforced. A match with another hex digit immediately before or after it is rejected, so the tool never carves a 64-character SHA-256 out of the first 64 characters of a 128-character SHA-512, and never reports a hash that is really a fragment of a longer blob.

Not identified by anything but length. The tool cannot know that a 32-character hex value is an MD5 hash rather than a random 128-bit token, or that a 40-character value is SHA-1 rather than a Git commit — nothing in the text distinguishes them. It also does not verify a hash, compute one, or reverse one; it only finds and classifies the strings.

Why the text never leaves your device

Matching runs as JavaScript in your browser. Nothing you paste is transmitted. For the full explanation of how browser-based processing works, see the security page.

This matters acutely for hashes. A list of hashes is frequently a set of indicators of compromise — the fingerprints of malware seen on a network — and pasting those into an online tool can tip off exactly the wrong party or leak the fact of an investigation. Extracting locally keeps the list on your machine.

What this tool does not do

This tool finds and classifies hashes by length. It deliberately does not:

Who extracts hashes

Hashes compared with UUIDs and other tokens

A hash is a digest of data, identified by its fixed length. A UUID is a 128-bit identifier with a distinctive 8-4-4-4-12 hyphenated shape. A MAC address is a 48-bit hardware address. All three are hex and all three turn up in the same operational logs, which is why the extractors sit together. For UUIDs use the UUID extractor; for hardware addresses, the MAC address extractor; for IPs, the IP address extractor.

If the value you are after is not one of these, the regex extractor lets you write your own pattern and runs it safely in your browser.

Frequently asked questions

How do I extract all hashes from a text file?

Paste the text above and click Extract. Every hash of a selected type is listed by length — MD5, SHA-1, SHA-256 and more — deduplicated and labelled.

How does it tell an MD5 from a SHA-256?

By length. MD5 is 32 hex characters, SHA-1 is 40, SHA-256 is 64 and SHA-512 is 128. Each length maps to exactly one algorithm, so the type is read straight from the string.

Can it crack or reverse a hash?

No. Hashes are one-way functions and the original input cannot be recovered. This tool only finds and classifies the digests in your text.

Will it mistake a Git commit for a hash?

A Git commit id is a 40-character SHA-1 and has the identical shape, so it is reported as SHA-1. Length alone cannot distinguish the two.

Are my hashes uploaded anywhere?

No. Everything runs in your browser. That matters because a hash list is often a set of indicators of compromise that should never be pasted into an online service.

Why was a hex string in my text ignored?

Only the exact lengths of real digests — 32, 40, 56, 64, 96 and 128 characters — are accepted. Any other length is skipped on purpose, which keeps tokens and version strings out.

Can it verify a file's checksum?

No. It extracts the checksums written in text; it does not hash a file to confirm a match. Use your operating system's hashing tool for that.

• Specialist file parsing & security engineer • Verified: in our experience, our hands-on testing measured and verified private in-browser execution with zero file uploads • Last reviewed August 2026.