Back to cases

Live public case

Opportunistic scan

Last activity Aug 27, 7:11:50 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not a confirmed compromise. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds, and the reviewed immutable HTTP records consistently classify the requests as php_or_wordpress_probe traffic from the same source cluster to target privatekind [http:[redacted], http:[redacted], http:[redacted]]. Sampled responses were redirects or rejections (301/404), with no request bodies [same references]. This supports a reconnaissance/enumeration verdict. It does not establish exploitation, command execution, persistence, or outbound activity; no process or flow evidence was cited by the incident and therefore those evidence tools could not provide corroboration.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Automated PHP/WordPress probe traffic reached target privatekind; reviewed HTTP events received 301 or 404 outcomes [http:[redacted], http:[redacted], http:4977296b-36bf-42d0-80ca-360cf377
  • Observed impact is limited to scanning and request handling; the cited HTTP evidence does not prove successful exploitation or workload compromise [http:[redacted], http:[redacted]].

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not a confirmed compromise. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds, and the reviewed immutable HTTP records consistently classify the requests as php_or_wordpress_probe traffic from the same source cluster to target privatekind [http:[redacted], http:[redacted], http:[redacted]]. Sampled responses were redirects or rejections (301/404), with no request bodies [same references]. This supports a reconnaissance/enumeration verdict. It does not establish exploitation, command execution, persistence, or outbound activity; no process or flow evidence was cited by the incident and therefore those evidence tools could not provide corroboration.