APTMembers
APT

Named firewall-rule deletion commands match two service artifacts

Two Windows processes were instructed to delete firewall rules named `upWire` and `wire`, matching service-registry artifacts for two files that share a signing certificate. The match makes component-specific maintenance or reconfiguration plausible, but the records do not show that either rule was deleted or establish who initiated the commands.

Oct 5, 2026, 15:15 (UTC+9)Last seenOct 5, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC37MITRE18

Two recorded Windows processes were launched with instructions to delete firewall rules named upWire and wire. Those same names appear in service-registry artifacts associated with two executables that share a code-signing certificate. The connection raises a more specific question than whether a firewall alert fired: was software managing rules associated with its own service components, or changing protections for another purpose?

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence