
Firewall-rule deletion attempts targeted reported service names
Two recorded commands targeted firewall rules named `upWire` and `wire`, which also appear in reported service locations for two distinct signed executables. The match connects their investigative footprints, but the records do not show whether either rule was removed or how the commands relate to the executables’ process ancestry.
Two recorded Windows commands targeted firewall rules named upWire and wire for deletion. Those names also appear in reported service autostart locations associated with two distinct signed executables. The match raises a more useful question than whether either file carries a suspicious label: what connects these programs’ service footprint to changes in the host’s network controls?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read