Tools / Hash Identifier
Hash Identifier
Paste any hash string to instantly identify its type. The tool checks the length, character set, and prefix against known hash formats including MD5, SHA family, bcrypt, NTLM, and common Unix crypt variants.
Identification result
Try an example
Hash length reference
| Algorithm | Hex length | Bits |
|---|---|---|
| CRC-32 / Adler-32 | 8 | 32 |
| MySQL 3.23 / CRC-64 | 16 | 64 |
| MD5 / NTLM / MD4 / LM | 32 | 128 |
| SHA-1 / RIPEMD-160 | 40 | 160 |
| SHA-224 / SHA3-224 | 56 | 224 |
| SHA-256 / SHA3-256 / SM3 | 64 | 256 |
| SHA-384 / SHA3-384 | 96 | 384 |
| SHA-512 / BLAKE2b / Whirlpool | 128 | 512 |
How it works
Most hex-encoded hashes can be identified purely by their character count. MD5 always produces 128 bits, which encodes to exactly 32 hex characters. SHA-1 produces 160 bits (40 hex chars), SHA-256 produces 256 bits (64 hex chars), and SHA-512 produces 512 bits (128 hex chars). If a hash uses a non-hex alphabet or has a recognizable prefix like $2a$ or $6$, the format can be determined immediately.
NTLM hashes are 32 hex characters - the same length as MD5. The key difference is that NTLM hashes are typically presented in uppercase. When you encounter an ambiguous 32-char hex hash, context matters: hashes from Windows environments are likely NTLM, while hashes from web applications are more likely MD5.
Hash challenges appear frequently in picoCTF forensics and cryptography categories. Look for hash-related challenges in the picoCTF 2024 and picoCTF 2025 crypto challenge sets.
Bcrypt hashes have a distinctive structure: they begin with $2a$, $2b$, or $2y$, followed by the cost factor (work factor) and then a 53-character Base64-encoded string combining salt and hash. The cost factor is a number like 10 or 12 that controls how many iterations are performed. SHA-512-crypt (used in modern Linux /etc/shadow) starts with $6$.
Once you have identified the hash type, the next step in a CTF is usually cracking it. Short or common passwords can be cracked with a wordlist attack using tools like hashcat or john. The correct hashcat mode number depends on the algorithm - for example, -m 0 for MD5, -m 100 for SHA-1, and -m 1800 for SHA-512-crypt. Identifying the type correctly before attempting to crack saves significant time.
In forensics challenges, hashes are also used to verify file integrity. If a challenge provides a hash alongside a downloaded file, verify that the hash matches before analyzing the file - a mismatch could indicate the file was modified or corrupted, which is itself sometimes a clue in the challenge.
Once you have identified the hash type here, use the Checksum Calculator to compute hashes of candidate inputs and verify them against the target. Together, these two tools cover the full identify-then-verify workflow common in CTF hash challenges.
Challenges that use this tool
Challenges where it helps
- Credential StuffingpicoCTF 2026 · Web Exploitation · Medium
- Fool the LockoutpicoCTF 2026 · Web Exploitation · Medium
- HashgatepicoCTF 2026 · Web Exploitation · Medium
- No FApicoCTF 2026 · Web Exploitation · Medium
- Password ProfilerpicoCTF 2026 · General Skills · Easy
- Secure Dot ProductpicoCTF 2026 · Cryptography · Hard
- Timestamped SecretspicoCTF 2026 · Cryptography · Medium
- ChronohackpicoCTF 2025 · Reverse Engineering · Medium
- Guess My Cheese (Part 2)picoCTF 2025 · Cryptography · Medium
- PachinkopicoCTF 2025 · Web Exploitation · Medium
- Classic Crackme 0x100picoCTF 2024 · Reverse Engineering · Medium
Browse the full challenge library for 11 more.
Guides that use this tool
- OSINT for CTF: How to Turn Public Data Into a FlagOSINT for CTF: identify a CVE from a prose description, recover redacted text, geolocate from EXIF, read identity out of a pcap, and profile credentials.
- PHP Type Juggling for CTF: Magic Hashes, Array Tricks, and What PHP 8 BrokeLoose comparison bugs in PHP, from 0e magic hashes to passing arrays into strcmp, plus which classic tricks PHP 8 killed and which ones still work in 2026.
- sqlmap for CTF: Every Flag That Matters, and What to Do When It Finds NothingA practical sqlmap workflow for CTF: request files, level and risk, technique selection, tamper scripts, second-order injection, and the failure checklist.
- Side-Channel Attacks for CTF: Timing, Power, Compression, and Cache OraclesRecover secrets from what a program leaks rather than what it outputs: timing leaks, correlation power analysis, compression oracles, and cache eviction channels.
- Bash Scripting for CTF Automation: Loops, Pipes, and Brute-Force HarnessesBash scripting for CTF automation: brute-force loops, curl and nc fuzzers, grep/awk/sed filtering, xargs parallelism, and a reusable solve.sh you can copy.
- Archive and Zip Password Cracking for CTFCrack password-protected zip, rar, and 7z archives in CTF. zip2john plus john and hashcat, fcrackzip wordlists, and the bkcrack known-plaintext attack on ZipCrypto.
Tools that pair with this one
- Checksum CalculatorCompute CRC32, MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes for text or uploaded files. Verify against known hashes.
- RSA CalculatorDecrypt RSA ciphertexts, factor n from the sum of primes, or generate key parameters. Handles arbitrarily large BigInt values.
- JWT DecoderDecode JSON Web Tokens and inspect the header, payload, and signature. Useful for web exploitation challenges.
- Strings ExtractorPull printable text from any binary, library, or image. ASCII and UTF-16 detection, configurable minimum length, flag-like highlight, no command line needed.
Or browse all 40 CTF tools.