search_hash

Pack: threatfox · Connect: https://pipeworx.io/mcp (see Connect below for a single-pack URL)

No MCP client? Call it directly: GET https://gateway.pipeworx.io/v1/tools/search_hash for the schema, then POST the same URL with its arguments for the data.

Everything ThreatFox knows about one file hash (md5 / sha1 / sha256), across BOTH relations it stores hashes in —

Parameters

NameTypeRequiredDescription
hashstringyesmd5 (32 hex), sha1 (40 hex) or sha256 (64 hex). Anything else is rejected upstream as illegl_hash [sic] rather than answered empty.

Example call

Arguments

{
  "hash": "2a85f2e5876b278a7af9393483de455b"
}

curl

curl -X POST https://gateway.pipeworx.io/threatfox/mcp \
  -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_hash","arguments":{"hash":"2a85f2e5876b278a7af9393483de455b"}}}'

TypeScript (@pipeworx/sdk)

import { Pipeworx } from '@pipeworx/sdk';
const pipeworx = new Pipeworx();

const result = await pipeworx.call('search_hash', {
  "hash": "2a85f2e5876b278a7af9393483de455b"
});

More examples

{
  "hash": "da168c3ff95c749beec0a2f29a1e6b82"
}

Response shape

Always returns: query, status, count, results

FieldTypeDescription
querystringThe query type sent (search_hash)
statusstring | nullQuery status (ok, no_result, or null)
countintegerNumber of results returned
resultsarrayIOCs associated with the file hash
matched_relationstring | nullWHICH of ThreatFox’s two hash relations answered. “sample_to_c2”: the hash is a malware sample and the rows are the C&C servers it talks to. “hash_listed_as_ioc”: the hash is itself published as an indicator (threat_type “payload”) and the row IS the answer. null: neither matched - both were searched, see searched_relations.
searched_relationsarrayPresent only when nothing matched: the relations that WERE searched, so an empty answer cannot be mistaken for a partial lookup.
Full JSON Schema
{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "The query type sent (search_hash)"
    },
    "status": {
      "type": [
        "string",
        "null"
      ],
      "description": "Query status (ok, no_result, or null)"
    },
    "count": {
      "type": "integer",
      "description": "Number of results returned"
    },
    "results": {
      "type": "array",
      "description": "IOCs associated with the file hash",
      "items": {
        "type": "object"
      }
    },
    "matched_relation": {
      "type": [
        "string",
        "null"
      ],
      "enum": [
        "sample_to_c2",
        "hash_listed_as_ioc",
        null
      ],
      "description": "WHICH of ThreatFox's two hash relations answered. \"sample_to_c2\": the hash is a malware sample and the rows are the C&C servers it talks to. \"hash_listed_as_ioc\": the hash is itself published as an indicator (threat_type \"payload\") and the row IS the answer. null: neither matched - both were searched, see searched_relations."
    },
    "searched_relations": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Present only when nothing matched: the relations that WERE searched, so an empty answer cannot be mistaken for a partial lookup."
    }
  },
  "required": [
    "query",
    "status",
    "count",
    "results"
  ]
}

Connect

Add this to your MCP client config — every tool in the catalog, including this one — or use one-click install buttons:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://pipeworx.io/mcp"
    }
  }
}
Connect to just the threatfox pack
{
  "mcpServers": {
    "threatfox": {
      "url": "https://gateway.pipeworx.io/threatfox/mcp"
    }
  }
}

See Getting Started for client-specific install steps.

Regenerated from source · build October 5, 2026