2b807893-889b-4dd8-99be-ff17aecfb58e

bootarm.efi :inline

This was provided by Microsoft and revoked May-23

  • UUID: 2b807893-889b-4dd8-99be-ff17aecfb58e
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\bootarm.efi } }
        
not set
Use CasePrivilegesOperating System
Persistence32-bit ARM
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • Black Lotus Microsoft Windows 10 version 1507
  • PropertyValue
    Filenamebootarm.efi
    MD5
    SHA1
    SHA25673DD7327621AA77D919473F71D3175EFA40F174D3C16060C079CEF169CC51363
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA2567D0B74AE42DF73A0C2C9CA64F6C83813D3D6A5C4B02BC47F566CEDD5682C691A
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31