dc00f1c1-898a-479d-b9a5-9caa9973e310

dc00f1c1-898a-479d-b9a5-9caa9973e310 :inline

This was provided by Unknown and revoked Jul-20

  • UUID: dc00f1c1-898a-479d-b9a5-9caa9973e310
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: |

Download

This download link contains the Revoked Bootloader!

          1
          bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\ } }
        
not set
Use CasePrivilegesOperating System
Persistence64-bit
Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed bootloader files
Expand

Names

detects loading using name only

Hashes

detects loading using hashes only
Expand

Block

on hashes

Alert

on hashes

  • https://uefi.org/revocationlistfile
  • https://support.microsoft.com/en-gb/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9ca

  • CVE-2020-10713
  • CVE-2020-14308
  • CVE-2020-14309
  • CVE-2020-14310
  • CVE-2020-14311
  • CVE-2020-15705
  • CVE-2020-15706
  • CVE-2020-15707
  • PropertyValue
    Filename
    MD5
    SHA1
    SHA25694BDE75194960FAFF8329DCB4462BD8888B32078B0FB8FB2011C6993FDA0316A
    Authentihash MD5
    Authentihash SHA1
    Authentihash SHA2569063F5FBC5E57AB6DE6C9488146020E172B176D5AB57D4C89F0F600E17FE2DE2
    Expand
    Expand
    Expand
    Expand
    Expand

    source

    last_updated: 2023-08-31