
Named firewall-rule deletion requests leave the outcome unresolved
Sandbox records show privileged requests to delete firewall rules named upWire and wire, names that also appear in reported service locations for two signed files. The overlap links the commands to a service-and-firewall-management footprint, but the records do not show whether either rule existed, was deleted or affected protection.
The Windows command in the sandbox record targets a specific firewall rule: netsh advfirewall firewall delete rule name="upWire". Another recorded command targets a rule named wire. Those names also appear in reported Windows service locations associated with two signed executable samples. The question is what that overlap establishes: software managing its own network-related settings, or a deliberate attempt to weaken protection?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read