Back to cases

Live public case

Opportunistic scan

Last activity Aug 31, 7:56:55 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration against target privatekind. The detector recorded 39 requests across 20 probe paths in roughly 4.3 seconds, and the inspected HTTP evidence confirms repeated GET requests categorized as php_or_wordpress_probe from one derived source cluster [http:[redacted]; http:[redacted]; http:[redacted]; http:[redacted]]. Inspected responses were redirects or 404 rejections; this supports detection of scanning but, because HTTP status alone is not dispositive, does not prove exploit failure. No cited process or flow evidence was available to establish execution or network consequences.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Repeated hostile enumeration traffic reached the HTTP service; sampled probes received 301 redirects or 404 responses [http:[redacted]; http:[redacted]; http:53dccde4-48be-49fb-bcbf-aa90e8
  • No command execution, persistence, lateral movement, outbound callback, or data loss is confirmed by the evidence available for this incident.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration against target privatekind. The detector recorded 39 requests across 20 probe paths in roughly 4.3 seconds, and the inspected HTTP evidence confirms repeated GET requests categorized as php_or_wordpress_probe from one derived source cluster [http:[redacted]; http:[redacted]; http:[redacted]; http:[redacted]]. Inspected responses were redirects or 404 rejections; this supports detection of scanning but, because HTTP status alone is not dispositive, does not prove exploit failure. No cited process or flow evidence was available to establish execution or network consequences.