Algorithms

NTLM

The NT hash Windows keeps for every password. MD4 of the password in UTF-16LE with no salt and no cost
IDntlm23 / 38MD · 128-bit
Hash / Legacy

NTLM

MD4 of a password in UTF-16LE, no salt at all.

Digest
128-bit · 16 bytes
HMAC
no key mode
Security
BROKEN as a password hash: no salt and no cost
Used by
Windows
3 options, 0 required

Sample

hex
e1cf2a4200eecdf14a4691bbf1ba255a
base64
4c8qQgDuzfFKRpG78bolWg==

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
roundsnumber
default 1
How many times to hash, each round hashing the previous digest
chainstring
default bytes
What each round after the first hashes: bytes of the digest, or its lowercase hex

Access

Createcreate("ntlm")
CLIhashes ntlm 'hello world'
Tryplayground with the sample above
Kinmd5, md4

The hash in a Windows SAM dump and the one pass-the-hash replays. It's MD4 over the password's UTF-16LE bytes, and that's the whole recipe. No salt. No cost. No rounds.

ts
create("ntlm").hash("password").digest; // "8846f7eaee8fb117ad06bdd830b7586c"
create("ntlm").hash("Password").digest; // "a4f49c406510bdcab6824ee7c30fd852"
create("md4").hash("password").digest; // "8a9d093f14f8701df17732b2bb182c74"

The last line is the usual mistake. MD4 of the UTF-8 bytes isn't the NT hash, every character needs its second byte.

So what does ntlm read? Text. Bytes go in as UTF-8 and come out as UTF-16LE, a BOM included. Bytes that aren't UTF-8 get a HashError, because there's no password they could spell. Hex input in a tool call or the CLI works the same way: 70617373776f7264 is password, and it gives 8846f7ea… too.

Same password, same hash, on every machine. One precomputed table covers every account that picked it. Hashcat calls this mode 1000. Here it's for checking what you found, not for storing anything.