Back to cases

Live public case

Opportunistic scan

Last activity Aug 26, 9:35:33 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not a confirmed compromise. The cited HTTP sequence contains repeated GET requests classified as PHP/WordPress probes from one traffic cluster over approximately 50 seconds (HTTP refs [redacted] through [redacted]). Retrieved examples were capture-complete, had empty request bodies, and returned consistent 404 responses. Those responses support rejection/non-discovery but, by themselves, do not prove that every possible exploit consequence was absent. No process- or flow-plane event references are cited by this incident, so execution and outbound-network consequences cannot be independently evaluated.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to handling rejected PHP/WordPress probe requests; cited HTTP examples returned 404 responses ([redacted], [redacted], [redacted]).
  • No command execution, persistence, lateral movement, command-and-control, or data theft is established by the available cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not a confirmed compromise. The cited HTTP sequence contains repeated GET requests classified as PHP/WordPress probes from one traffic cluster over approximately 50 seconds (HTTP refs [redacted] through [redacted]). Retrieved examples were capture-complete, had empty request bodies, and returned consistent 404 responses. Those responses support rejection/non-discovery but, by themselves, do not prove that every possible exploit consequence was absent. No process- or flow-plane event references are cited by this incident, so execution and outbound-network consequences cannot be independently evaluated.