A tester uses Mimikatz on a compromised Windows workstation to extract the following credential pair from LSASS memory: aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c. The tester wants to crack the second hash value offline using hashcat. Which hashcat mode should the tester specify?
- A-m 0 (MD5)
- B-m 5500 (NetNTLMv1)
- C-m 1800 (sha512crypt)
- D-m 1000 (NTLM)
Show answer & explanationAnswer & explanation
Correct answer: D. -m 1000 (NTLM)
The format LM:NTLM (with the LM hash showing the well-known empty-password constant aad3b435b51404eeaad3b435b51404ee) is characteristic of Windows SAM/LSASS credential dumps; the second 32-character hex value is the NTLM hash, cracked in hashcat with mode 1000. MD5 (-m 0) and sha512crypt (-m 1800) are different hash algorithms entirely, and NetNTLMv1 (-m 5500) is a network authentication hash format, not a locally stored NTLM hash.
Why the other options are wrong
- A. MD5 mode 0 is for generic MD5 hashes, unrelated to Windows NTLM credential storage format.
- B. NetNTLMv1 (mode 5500) is a network challenge-response hash captured during authentication, not a static LSASS hash dump.
- C. sha512crypt (mode 1800) is a Unix/Linux password hashing scheme, not used by Windows NTLM.
NTLM Hash Identification
Windows credential dumps typically appear as LM:NTLM pairs; the constant aad3b435b51404eeaad3b435b51404ee indicates an empty/disabled LM hash, and the following 32 hex characters are the NTLM hash, cracked with hashcat mode 1000.
- LM hash constant aad3b435b51404eeaad3b435b51404ee means LM hashing is disabled or blank
- NTLM hashes are cracked using hashcat mode 1000
- NetNTLMv1/v2 (modes 5500/5600) are different — they're network authentication responses, not static hashes
Memory trick: aad3b435... = LM's ghost hash; the real NTLM hash follows the colon