What Hashcat does and why you'd use it for RAR files
Hashcat is a password-recovery tool that tests thousands of password guesses against an encrypted file in seconds. For RAR files locked with a password, Hashcat extracts the encrypted hash from the file, then runs it against a list of candidate passwords you provide — either a dictionary file or patterns you define. If one matches, you get the password back.
You would use this when you have a RAR file you created yourself but forgot the password, or when you have legitimate access to a file and need to recover it. Hashcat works on Windows, Linux, and macOS, and uses your graphics card (GPU) to speed up the process dramatically compared to CPU-only tools.
The process has three parts: extracting the hash from the RAR file, preparing your password list, and running Hashcat against it. Each step matters — a weak password list means Hashcat will never find the answer, even if the password is simple.
Key Takeaways
- Hashcat requires you to first extract the RAR file's hash using a tool like rar2john, which converts the encrypted data into a format Hashcat understands.
- Your success depends entirely on your password list — Hashcat can only find passwords that exist in the file or pattern you give it.
- GPU acceleration makes Hashcat fast, but you need a compatible graphics card (NVIDIA, AMD, or Intel) and the correct drivers installed.
- RAR5 format (used in WinRAR 5.0 and later) is significantly slower to crack than older RAR3 format, so recovery time varies widely based on which RAR version created the file.
Installing Hashcat and checking your system
Download Hashcat from hashcat.net/hashcat — the official site only. Extract the folder to a location you can access from the command line. On Windows, many users put it in C:\hashcat or their Documents folder. On Linux or macOS, /opt/hashcat or your home directory works.
Before you start, verify your graphics card is supported. Hashcat works best with NVIDIA GPUs (most common), AMD GPUs, or Intel Arc cards. Open a terminal or command prompt in your Hashcat folder and run hashcat -I (capital I). This lists every GPU Hashcat detects. If you see your graphics card listed, you're ready. If not, you may need to install or update GPU drivers — NVIDIA users should install CUDA, AMD users need HIP or the AMD driver, and Intel users need the Intel GPU drivers.
If you have no compatible GPU, Hashcat will still run on your CPU, but it will be much slower — sometimes 10 to 100 times slower depending on your processor and the RAR version. CPU-only cracking is practical only for very weak passwords or very small password lists.
Extracting the hash from your RAR file
Hashcat cannot read RAR files directly. You need to extract the encrypted hash first using rar2john, a tool included in the John the Ripper suite. Download John the Ripper from openwall.com/john — use the community version (free). Extract it, then locate the rar2john executable inside.
Open a command prompt or terminal and navigate to where you have both your RAR file and rar2john. Run this command:
rar2john yourfile.rar > hash.txt
Replace "yourfile.rar" with your actual filename. This extracts the hash and saves it to a file called hash.txt. Open hash.txt in a text editor to verify it contains a long string of characters — that's the encrypted data Hashcat will work against. If the file is empty or shows an error, the RAR file may be corrupted or rar2john did not recognize it.
Preparing your password list or attack pattern
Hashcat needs candidate passwords to test. You provide these in one of three ways: a dictionary file (a text file with one password per line), a pattern you define (like "password" plus numbers 0-9999), or a combination of both called a rule.
For a dictionary approach, download a password list. Common sources include SecLists (github.com/danielmiessler/SecLists), which has lists organized by size and type. Download a file like rockyou.txt (14 million common passwords) or a smaller list if you want faster results. Place the file in your Hashcat folder or note its full path.
For a pattern approach, you define a mask. For example, ?l?l?l?l?d?d?d?d means four lowercase letters followed by four digits — this would test passwords like "abcd1234", "aaaa0000", etc. Masks are faster when you remember part of the password or know its structure. Hashcat's documentation lists all mask characters: ?l (lowercase), ?u (uppercase), ?d (digit), ?s (special character).
Running Hashcat against the RAR hash
Open a command prompt or terminal in your Hashcat folder. The basic command is:
hashcat -m 13000 hash.txt dictionary.txt
Here, -m 13000 is the hash type for RAR3 (older RAR format). If your file is RAR5 format (WinRAR 5.0+), use -m 13200 instead. hash.txt is your extracted hash file, and dictionary.txt is your password list. If you're using a mask instead, replace dictionary.txt with -a 3 (attack mode 3 for mask) followed by your mask:
hashcat -m 13000 hash.txt -a 3 ?l?l?l?l?d?d?d?d
Hashcat will start testing passwords. You'll see a progress bar, speed (passwords per second), and estimated time remaining. On a modern GPU with a large dictionary, you might test millions of passwords per second. On a CPU, expect thousands. If Hashcat finds the password, it displays it on screen and saves it to a file called potfile in the Hashcat folder.
Understanding why the password might not be found
If Hashcat finishes without finding the password, the most common reason is that your password list does not contain it. A 14-million-word dictionary covers most common passwords, but if the password is uncommon, random, or a phrase, it won't be in any standard list. You would need to either expand your dictionary, adjust your mask to cover more possibilities, or use a rule to modify passwords (like adding numbers to the end of dictionary words).
The second reason is that you used the wrong hash type. RAR3 and RAR5 are different — if you extracted from a RAR5 file but ran Hashcat with -m 13000, it will never match. Check your RAR file's properties or try opening it in WinRAR to see the format version. If you're unsure, try both hash types.
The third reason is a corrupted hash extraction. If rar2john produced an empty file or an error, the hash may be incomplete. Try extracting again, or verify the RAR file itself is not corrupted by attempting to open it in WinRAR (it will ask for the password but should not show a corruption error).
Speeding up the process with rules and optimization
If you have a small dictionary but suspect the password is a variation of a common word, use a rule file. Rules modify each password in your dictionary — for example, adding numbers, capitalizing the first letter, or appending common suffixes. Hashcat includes rule files in its rules folder. To use one:
hashcat -m 13000 hash.txt dictionary.txt -r rules/best64.rules
This tests not just the words in your dictionary, but also variations of them. It's slower than a plain dictionary attack but covers far more ground than the dictionary alone.
You can also combine multiple dictionaries or use the -o flag to save the result to a specific file. For RAR5 files, which are slower to crack, consider starting with a smaller, more targeted dictionary (common passwords, words related to the file's purpose) before moving to larger lists.
Frequently Asked Questions
What's the difference between RAR3 and RAR5, and why does it matter?
RAR3 is the older format (WinRAR versions before 5.0) and uses weaker encryption that Hashcat can test quickly. RAR5 uses stronger encryption and is deliberately slower to crack — testing each password takes longer. If you're cracking RAR5, expect the process to take 10 to 100 times longer than RAR3 with the same hardware and password list.
Can I use Hashcat on a laptop without a dedicated graphics card?
Yes, but it will be slow. Hashcat can use your CPU, but CPU-only cracking is practical only for very weak passwords or very small password lists. If you have an integrated Intel or AMD GPU, Hashcat may detect and use it, which is faster than CPU alone. Check with hashcat -I to see what your system has available.
Where do I find good password lists to download?
SecLists (github.com/danielmiessler/SecLists) is the most comprehensive free source. It includes rockyou.txt (14 million passwords), smaller curated lists, and lists organized by category. Download only what you need — a 14-million-word list is large and will take longer to process than a 1-million-word list.
What if Hashcat says "No hashes loaded" when I run it?
This usually means the hash file is empty or in the wrong format. Verify that rar2john produced output by opening hash.txt in a text editor — it should contain a long string starting with the filename. If it's empty, try running rar2john again or check that the RAR file is not corrupted.
How long will it take to crack my password?
It depends on three things: your GPU speed (measured in passwords per second), the size of your password list, and whether you're using RAR3 or RAR5. A modern GPU testing a 14-million-word dictionary against RAR3 might take minutes to hours. The same dictionary against RAR5 could take days. If you know part of the password, a targeted mask will be much faster than a full dictionary.