You could possibly create a script that continuously crawls your entire filesystem and logs the following:
modtime filename sha1sum
Then you could index that log file and find the files you are after and the modtime they had that sha1sum.
But it's not possible to compare an arbitrary sha1sum to the current filesystem with Splunk. Although you could potentially create some kind of custom command.