CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A tester uses Mimikatz on a compromised Windows workstation to extract the following credential pair from LSASS memory: aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c. The tester wants to crack the second hash value offline using hashcat. Which hashcat mode should the tester specify?

  1. A-m 0 (MD5)
  2. B-m 5500 (NetNTLMv1)
  3. C-m 1800 (sha512crypt)
  4. D-m 1000 (NTLM)
Show answer & explanation

Correct answer: D. -m 1000 (NTLM)

The format LM:NTLM (with the LM hash showing the well-known empty-password constant aad3b435b51404eeaad3b435b51404ee) is characteristic of Windows SAM/LSASS credential dumps; the second 32-character hex value is the NTLM hash, cracked in hashcat with mode 1000. MD5 (-m 0) and sha512crypt (-m 1800) are different hash algorithms entirely, and NetNTLMv1 (-m 5500) is a network authentication hash format, not a locally stored NTLM hash.

Why the other options are wrong

  • A. MD5 mode 0 is for generic MD5 hashes, unrelated to Windows NTLM credential storage format.
  • B. NetNTLMv1 (mode 5500) is a network challenge-response hash captured during authentication, not a static LSASS hash dump.
  • C. sha512crypt (mode 1800) is a Unix/Linux password hashing scheme, not used by Windows NTLM.

NTLM Hash Identification

Windows credential dumps typically appear as LM:NTLM pairs; the constant aad3b435b51404eeaad3b435b51404ee indicates an empty/disabled LM hash, and the following 32 hex characters are the NTLM hash, cracked with hashcat mode 1000.

  • LM hash constant aad3b435b51404eeaad3b435b51404ee means LM hashing is disabled or blank
  • NTLM hashes are cracked using hashcat mode 1000
  • NetNTLMv1/v2 (modes 5500/5600) are different — they're network authentication responses, not static hashes

Memory trick: aad3b435... = LM's ghost hash; the real NTLM hash follows the colon

More Attacks and Exploits questions