34cf714a-cbf0-4339-afb8-bae3643a4075

bootmgfw.efi :inline

This was provided by Microsoft and revoked May-23

  • UUID: 34cf714a-cbf0-4339-afb8-bae3643a4075
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\bootmgfw.efi } }
        
not set
Use CasePrivilegesOperating System
Persistence32-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • Black Lotus Microsoft Windows 8
  • PropertyValue
    Filenamebootmgfw.efi
    MD5
    SHA1
    SHA256AA38D5E097A9853A25A1DAA838ED83BC43569DB871FDF24888512A434024A866
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA256FE0E58846C40717FEDE6A1E0D6A0546CBF8B8CF0B82258FC16D05BAB58107D34
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31