1a268d88-47d0-4204-ade4-ed6e4ef6028e

bootia32.efi :inline

This was provided by Microsoft and revoked May-23

  • UUID: 1a268d88-47d0-4204-ade4-ed6e4ef6028e
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\bootia32.efi } }
        
not set
Use CasePrivilegesOperating System
Persistence32-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • Black Lotus Microsoft Windows 10 version 1507
  • PropertyValue
    Filenamebootia32.efi
    MD5
    SHA1
    SHA256B510C9A79CB6CE1BC37912839AF57B453CC4A77C3D5DCC9935F8CCFF7C81F9FE
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA256D79651AA3A0491D33B7979F5B41936F8ACEFBA99BBA10E05FD6F54E2859CC589
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31