78f886c7-28cd-4686-ac8f-ee82f3e0fbcb

78f886c7-28cd-4686-ac8f-ee82f3e0fbcb :inline

This was provided by BITDEFENDER and revoked Jul-20

  • UUID: 78f886c7-28cd-4686-ac8f-ee82f3e0fbcb
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\ } }
        
not set
Use CasePrivilegesOperating System
Persistence64-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • CVE-2020-10713
  • CVE-2020-14308
  • CVE-2020-14309
  • CVE-2020-14310
  • CVE-2020-14311
  • CVE-2020-15705
  • CVE-2020-15706
  • CVE-2020-15707
  • PropertyValue
    Filename
    MD5
    SHA1
    SHA256A95666BFAF48FD9C4CAF2F3ED4EB593145C48BD3C93E4B00638088CE7EE962CF
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA256D89A11D16C488DD4FBBC541D4B07FAF8670D660994488FE54B1FBFF2704E4288
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31