Back to cases

Live public case

Opportunistic scan

Last activity Aug 19, 5:50:16 AM PDT

mediumNot requiredResolved · Authorized test

Evidence-grounded assessment

Not required

This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.

Shared case lifecycle

Resolved · Authorized test

This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.

Observed impact

  • The target received 331 rapid web-shell-path probes spanning 167 unique paths [[redacted], [redacted], [redacted], [redacted], 1147abb7-
  • [redacted], [redacted], [redacted], [redacted], [redacted], [redacted], 3ca390a0-48e
  • The observed HTTP consequence was limited to redirects or rejections; no successful exploitation consequence is demonstrated by the available evidence [[redacted], [redacted], 3ca390a0-48e

Recommended actions

    Attack timeline

    1 incident threads

    Resolution changes operator work, not the preserved attack evidence below.

    1. 1
      Opportunistic scanopen

      This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.