f901491e-f41b-4b77-8f9f-f9e5a6f03c8c
shim-15+1533136590.3beb971-0ubuntu1/shim64-bit.efi
Description
This was provided by Canonical Ltd and revoked Apr-21
This download link contains the Revoked Bootloader!
Commands
bcdedit /copy "{current}" /d "TheBoots" | {% if ($_ -match '{\S+}') { bcdedit /set $matches[0] path \windows\temp\shim-15+1533136590.3beb971-0ubuntu1/shim64-bit.efi } }
Use Case | Privileges | Operating System |
---|---|---|
Persistence | 64-bit |
Detections
YARA 🏹
Expand
with header and size limitation
without header and size limitation
for renamed bootloader files
Resources
CVE
Known Vulnerable Samples
Property | Value |
---|---|
Filename | shim-15+1533136590.3beb971-0ubuntu1/shim64-bit.efi |
MD5 | 9c9e2e8f49820dbed91f5cae846bbadb |
SHA1 | afc56df60e5ea5a55a1e21f76562d073a56ec46b |
SHA256 | 8844d9b3aea1568a7ff298e6dc12564c422dafae6510db377454ca6072861dde |
Authentihash MD5 | 75a7ca7cd2451ad3190c71a38c41ca02 |
Authentihash SHA1 | a60d97d18e48c13e38723508639f0600aa6888f9 |
Authentihash SHA256 | 5bfe928eec15454be29504e8f592a4ce5908afe3284b9eeeb259b25145eea2ab |
RichPEHeaderHash MD5 | ffdf660eb1ebf020a1d0a55a90712dfb |
RichPEHeaderHash SHA1 | 3e905e3d061d0d59de61fcf39c994fcb0ec1bab3 |
RichPEHeaderHash SHA256 | 2b3f99a94b7a7132854be769e27b331419c53989ef42f686d6f5ba09ddefefd6 |
Imports
Expand
Imports
Expand
ImportedFunctions
Expand
ExportedFunctions
Expand
Signature
Expand
last_updated: 2023-08-31