πŸ”Ž IOC Analyzer

Paste a single indicator of compromise β€” IPv4, IPv6, domain, URL, MD5, SHA-1, or SHA-256 β€” and the type is detected automatically. Context is gathered from this site’s existing lookup tools. Nothing here labels an indicator malicious or benign without a real reputation source.

Input

One indicator at a time. Private, loopback, and internal addresses are not looked up.

Results

How It Works

The tool inspects the format of what you paste and picks the matching analysis: IP addresses get geolocation, ASN, organization, and reverse DNS; domains get DNS records, RDAP registration data, and TLS status; URLs are broken into their components and resolved, with HTTP status, redirect, and TLS details; hashes are identified by length and normalized to lowercase.

What it deliberately does not do: it does not call a hash "malicious" or "clean" β€” that requires a real threat-intelligence source, and none is configured for hashes. Geolocation is approximate. For IP reputation signals, use the IP Reputation tool.

Examples & Common Use Cases

  • 8.8.8.8 β†’ detected as an IPv4 address, with network and location context.
  • example.com β†’ detected as a domain, with DNS, RDAP, and TLS status.
  • https://example.com/login?id=1 β†’ detected as a URL, broken into parts and checked safely.
  • A 32/40/64-character hexadecimal string β†’ identified as MD5/SHA-1/SHA-256.