
Named firewall-rule deletion commands match two service artifacts
Two Windows processes were instructed to delete firewall rules named `upWire` and `wire`, matching service-registry artifacts for two files that share a signing certificate. The match makes component-specific maintenance or reconfiguration plausible, but the records do not show that either rule was deleted or establish who initiated the commands.
Two recorded Windows processes were launched with instructions to delete firewall rules named upWire and wire. Those same names appear in service-registry artifacts associated with two executables that share a code-signing certificate. The connection raises a more specific question than whether a firewall alert fired: was software managing rules associated with its own service components, or changing protections for another purpose?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read