Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ntlmv1-multi — NTLMv1 Multitool | Kitploit
Tools/GitHubGitHub/evilmog/ntlmv1-multi
Password CrackingEncryption/Decryption ToolsPassword AttacksHash AnalysisCryptographyAuthentication
GitHubevilmog/ntlmv1-multi

ntlmv1-multi

NTLMv1 Multitool

View Repository
67099233 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

NTLMv1 Multi Tool

This tool reverses NTLMv1 hashes to NTLM, or more specifically it formats NTLMv1 challenge responses into a format that can be cracked with hashcat mode 14000

CT3 calculation

If you specify --ct3 it will calculate the the final 4 digits of the NTLM for you, if you specify --json then --ct3 is implied ansd it will return as the element pt3, eg:

python3 ntlmv1.py --ntlm "DC1$::MOG:AC51EC464A91A35A04A862DA3106EC2B352661ECEF909C5E:AC51EC464A91A35A04A862DA3106EC2B352661ECEF909C5E:1122334455667788" --json 

{"ntlmv1": "DC1$::MOG:AC51EC464A91A35A04A862DA3106EC2B352661ECEF909C5E:AC51EC464A91A35A04A862DA3106EC2B352661ECEF909C5E:1122334455667788", "user": "DC1$", "domain": "MOG", "challenge": "1122334455667788", "lmresp": "AC51EC464A91A35A04A862DA3106EC2B352661ECEF909C5E", "ntresp": "AC51EC464A91A35A04A862DA3106EC2B352661ECEF909C5E", "ct3": "352661ECEF909C5E", "ct3_crack": "ct3_to_ntlm.bin 352661ECEF909C5E 1122334455667788", "pt3": "8c71", "hash1": "AC51EC464A91A35A:1122334455667788", "hash2": "04A862DA3106EC2B:1122334455667788"}

Finally in this update I have moved the functions into main() so that you can just import the module for direct use

10 Nov, 2020 Updates

I added 2 new options, --hashcat and --hcutils these set the path to your hashcat and hashcat-utils respectively so you can do a direct copy and paste from the tool.

You would run the tool like this if your hashcat directory was in ~/git/hashcat and your hashcat-utils directory was in ~/git/hashcat-utils:

python3 ./ntlmv1.py --ntlm "SERVER1$::MOG:9DE7F41D81C1207400000000000000000000000000000000:DE766A98B60D1C911DCFFFDBB3E521314B2CE34EAB63CC7B:1122334455667788" --hashcat "~/git/hashcat" --hcutils "~/git/hashcat-utils"

Dec 10, 2019 Updates

Yes this is supposedly python 3 compatible, I have also merged ntlmv1 and ntlmv1-ess

ntlmv1-multi

NTLMv1 Multitool

This tool modifies NTLMv1/NTLMv1-ESS/MSCHAPv2 hashes so they can be cracked with DES Mode 14000 in hashcat

This tool is based on work done by atom of team Hashcat https://hashcat.net/forum/thread-5832.html

It is also based on https://hashcat.net/forum/thread-5912.html and https://www.youtube.com/watch?v=LIHACAct2vo

Install

Install the ntlmv1_nextgen.py next-gen tool as a global ntlmv1-multi command with uv:

uv tool install .
ntlmv1-multi --ntlmv1 "hashcat::DUSTIN-5AA37877:76365E2D142B5612980C67D057EB9EFEEE5EF6EB6FF6E04D:727B4E35F947129EA52B9CDEDAE86934BB23EF89F50FC595:1122334455667788"

Or run it directly from the repo without installing:

uv run ntlmv1_nextgen.py --ntlmv1 "hashcat::DUSTIN-5AA37877:..."

The project ships a pyproject.toml (Python 3.14+, pycryptodome dependency) so uv resolves everything for you; the original ntlmv1.py still runs standalone with any Python 3 interpreter.

Next-gen tool (ntlmv1_nextgen.py)

ntlmv1_nextgen.py (installed as the ntlmv1-multi command) is the modern parser. It accepts NTLMv1, $99$ blobs, and MSCHAPv2, handles ESS automatically, and can finish the full NTLMv1 -> NTLM conversion from a cracked potfile in one step. Available options:

OptionDescription
--ntlmv1 <hash>NTLMv1 hash in Responder format (user::host:LM:NT:challenge).
--99 <blob>$99$-style base64 blob.
--mschapv2 <hash>MSCHAPv2 hash in John the Ripper format.
--nthash <hex>32-char NTLM hash; derives the DES keys and hashcat candidates.
--password <pw>Derive the --key1/--key2 DES keys from a known password.
--key1 <hex> / --key2 <hex>Supply the 16-hex DES keys for CT1/CT2 directly (takes precedence over --potfile).
--potfile <path>hashcat/rainbowcrackalack potfile of cracked mode 14000 keys; recovers key1/key2 automatically to complete the NTLMv1 -> NTLM conversion.
--hashcatEmit hashcat-format strings for CT1/CT2.
--jsonOutput JSON only (implies CT3 calculation).

Usage

NTLMv1 without ESS

To capture use responder with the --lm flag, without --lm you will activate ESS which will take longer to crack, also a new flag is out --disable-ess which will try to disable ESS and force the downgrade. Try --disable-ess first and if that fails please try --lm. If using --disable-ess or --lm ensure your client challenge is 1122334455667788 to use the FPGA, however this may trigger some network IDS/IPS protections if they see that traffic.

The capture will look like this.

[SMB] NTLMv1 Client   : 184.64.60.62
[SMB] NTLMv1 Username : DUSTIN-5AA37877\hashcat
[SMB] NTLMv1 Hash     : hashcat::DUSTIN-5AA37877:76365E2D142B5612980C67D057EB9EFEEE5EF6EB6FF6E04D:727B4E35F947129EA52B9CDEDAE86934BB23EF89F50FC595:1122334455667788
[*] Skipping previously captured hash for DUSTIN-5AA37877\hashcat

The hash portion looks like this

hashcat::DUSTIN-5AA37877:76365E2D142B5612980C67D057EB9EFEEE5EF6EB6FF6E04D:727B4E35F947129EA52B9CDEDAE86934BB23EF89F50FC595:1122334455667788

So use the multi tool like so (its also python 2 compatible)

python3 ntlmv1.py --ntlmv1 hashcat::DUSTIN-5AA37877:76365E2D142B5612980C67D057EB9EFEEE5EF6EB6FF6E04D:727B4E35F947129EA52B9CDEDAE86934BB23EF89F50FC595:1122334455667788

It will output the following data without modifing server challenges etc

['hashcat', '', 'DUSTIN-5AA37877', '76365E2D142B5612980C67D057EB9EFEEE5EF6EB6FF6E04D', '727B4E35F947129EA52B9CDEDAE86934BB23EF89F50FC595', '1122334455667788']

Hostname: DUSTIN-5AA37877
Username: hashcat
Challenge: 1122334455667788
LM Response: 76365E2D142B5612980C67D057EB9EFEEE5EF6EB6FF6E04D
NT Response: 727B4E35F947129EA52B9CDEDAE86934BB23EF89F50FC595
CT1: 727B4E35F947129E
CT2: A52B9CDEDAE86934
CT3: BB23EF89F50FC595

To Calculate final 4 characters of NTLM hash use:
./ct3_to_ntlm.bin BB23EF89F50FC595 1122334455667788

To crack with hashcat create a file with the following contents:
727B4E35F947129E:1122334455667788
A52B9CDEDAE86934:1122334455667788

To crack with hashcat:
./hashcat -m 14000 -a 3 -1 charsets/DES_full.charset --hex-charset hashes.txt ?1?1?1?1?1?1?1?1

The password used in this case is "password" and we can verify the ntlm hash with

echo -n password | iconv -f utf8 -t utf16le | openssl dgst -md4
(stdin)= 8846f7eaee8fb117ad06bdd830b7586c

With hashcat utils ct3_to_ntlm.bin that atom wrote you can calculate the last 4 characters of the NTLM hash from the NTLMv1 challenge, which the tool outputs

./ct3_to_ntlm.bin BB23EF89F50FC595 1122334455667788
586c

This matches up to the end of the ntlm hash so we are good to go, the next step is cracking the hashes with hashcat so we need to make a hashes.txt file with

727B4E35F947129E:1122334455667788
A52B9CDEDAE86934:1122334455667788

To crack this with hashcat you use

./hashcat -m 14000 -a 3 -1 charsets/DES_full.charset --hex-charset hashes.txt ?1?1?1?1?1?1?1?1

An important note is that hashcat will return DES keys and not NTLM keys, you will need to convert to NTLM using deskey_to_ntlm.pl from Hashcat Utils, this can be accomplished with

./deskey_to_ntlm.pl [cracked des key 1]
./deskey_to_ntlm.pl [cracked des key 2]

you then combine the two ntlm keys with the third part of the password. Calculated by (whatever the tool outputs)

./ct3_to_ntlm.bin BB23EF89F50FC595 1122334455667788

Add those 3x together and you are good to go

Testing with the des converter

If you are just testing my code and know the password already you can use the des converter

python ntlm-to-des.py --ntlm b4b9b02e6f09a9bd760f388b67351e2b
DESKEY1: b55d6d04e67926
DESKEY2: bcba83e6895b9d

echo "$HEX[b55d6d04e67926]">>des.cand
echo "$HEX[bcba83e6895b9d]">>des.cand

Basically you do the following

echo "$HEX[b55d6d04e67926]">>des.cand
echo "$HEX[bcba83e6895b9d]">>des.cand
./hashcat -m 14000 -a 0 hashes.txt des.cand

And you should have some reversed hashes

Download Tool