
upWire analysis shows attempted deletion of two named firewall rules
Two elevated command-shell events associated with upWire launched commands to delete firewall rules named upWire and wire; a separate wire.exe file has a reported service-registry location. The matching name makes a host-configuration link worth investigating, but the records do not show that either rule was removed or establish a continuous installation sequence.
Two Windows command-shell events in an analysis associated with upWire launched netsh.exe with instructions to delete firewall rules named upWire and wire. A separate file identified as wire.exe has a reported registry location under Services\wire. Together, these observations raise a more specific question than whether a suspicious executable used a Windows administration tool: do the matching names reveal how related software manages its presence on the host?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read