C&CMembers
C&C

upWire analysis shows attempted deletion of two named firewall rules

Two elevated command-shell events associated with upWire launched commands to delete firewall rules named upWire and wire; a separate wire.exe file has a reported service-registry location. The matching name makes a host-configuration link worth investigating, but the records do not show that either rule was removed or establish a continuous installation sequence.

Oct 11, 2026, 15:50 (UTC+9)Last seenOct 11, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC61MITRE18

Two Windows command-shell events in an analysis associated with upWire launched netsh.exe with instructions to delete firewall rules named upWire and wire. A separate file identified as wire.exe has a reported registry location under Services\wire. Together, these observations raise a more specific question than whether a suspicious executable used a Windows administration tool: do the matching names reveal how related software manages its presence on the host?

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence