64c9ea42-80a1-425d-ae59-d9ee4eadf4ba

BOOTX64.EFI :inline

This was provided by Red Hat Inc. and revoked Jul-20

  • UUID: 64c9ea42-80a1-425d-ae59-d9ee4eadf4ba
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\BOOTX64.EFI } }
        
not set
Use CasePrivilegesOperating System
Persistence64-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • CVE-2020-10713
  • CVE-2020-14308
  • CVE-2020-14309
  • CVE-2020-14310
  • CVE-2020-14311
  • CVE-2020-15705
  • CVE-2020-15706
  • CVE-2020-15707
  • PropertyValue
    FilenameBOOTX64.EFI
    MD5
    SHA1
    SHA256BDD96B78F3AA4B123851342995451880CB2498E785ED12E48CEB36F1A3F49B2B
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA256A924D3CAD6DA42B7399B96A095A06F18F6B1ABA5B873B0D5F3A0EE2173B48B6C
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31