Check out the example hashes from hashcat here: https://hashcat.net/wiki/doku.php?id=example_hashes Specifically in this case the #5600 for NetNTLMv2; that should be how your hash is formatted and the portions that you would need for cracking it.   That was the type of hashes i was getting from this attack, however you may want to look at other ones on that page in case you are getting other kinds.  They do look different then the ones I was getting looking at the screenshot.