09476ffd-a0fd-4510-9e36-a20727c16b8c

bootmgfw.efi :inline

This was provided by Microsoft and revoked May-23

  • UUID: 09476ffd-a0fd-4510-9e36-a20727c16b8c
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\bootmgfw.efi } }
        
not set
Use CasePrivilegesOperating System
Persistence32-bit ARM
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • Black Lotus Microsoft Windows 10 version 1507
  • PropertyValue
    Filenamebootmgfw.efi
    MD5
    SHA1
    SHA256A97E2E39DA89F16E0AFB9CF3A213205ED00BF2200A573812B5C5F56FDB8B2402
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA2565AAFC9F5F98DB75F8519D8652924932939760F00DF8827FA2A6E36DB265F21F8
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31