Back to cases

Live public case

Opportunistic scan

Last activity Aug 21, 4:35:02 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is strongly consistent with genuine opportunistic reconnaissance for exposed PHP/WordPress web shells. Verified HTTP summaries show rapid GET probes categorized as php_or_wordpress_probe against target privatekind, with 301 redirects or 404 rejections. The derived detector reports 39 requests covering 20 unique probe paths in about 11 seconds. Available evidence establishes the scan attempt, but not web-shell presence, command execution, or compromise; no process or flow evidence references are cited by this incident.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • The target was exposed to rapid opportunistic enumeration of suspected PHP and WordPress web-shell locations.
  • No confirmed execution, persistence, outbound activity, or other workload compromise is established by the available cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is strongly consistent with genuine opportunistic reconnaissance for exposed PHP/WordPress web shells. Verified HTTP summaries show rapid GET probes categorized as php_or_wordpress_probe against target privatekind, with 301 redirects or 404 rejections. The derived detector reports 39 requests covering 20 unique probe paths in about 11 seconds. Available evidence establishes the scan attempt, but not web-shell presence, command execution, or compromise; no process or flow evidence references are cited by this incident.