Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 22, 12:23:38 PM PDT
Evidence through
Aug 22, 12:23:57 PM PDT
AI status
Complete
True positive98% confidence

True positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The HTTP evidence shows rapid GET probes from one derived source cluster, categorized as PHP/WordPress probes, including the first and last cited events [http:[redacted]; http:[redacted]]. The detector aggregated 38 requests over 20 unique probe paths and recorded only redirects or rejections across the cited set. No process or flow evidence is cited by this incident, so execution, outbound connectivity, persistence, or other compromise consequences are not established.

Attack stage
Reconnaissance: PHP/WordPress web-shell path enumeration
Model
gpt-5.6-sol · 7 evidence calls

Observed impact

  • Attempted discovery of exposed PHP/WordPress web-shell resources; the observed HTTP outcome was redirect or rejection only [http:[redacted]; http:[redacted]; http:7fff9a16-9749-4e7b-a4c0-8

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

149 observations · 12 http

Explicit uncertainty

  • The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • Downstream workload affinity is inferred from configured routing and is not an observed per-request trace edge.
  • No process or flow evidence references are cited by this incident; therefore, the available evidence cannot determine whether any execution or outbound connection occurred outside the bounded HTTP observations.
  • Exact request paths and raw response bodies are intentionally unavailable in the bounded summaries, so the specific filenames tested and the content of the 404 response cannot be independently inspected.

Recommended actions

  1. Retain or confirm edge rejection and redirect controls for known PHP/WordPress web-shell paths, and monitor the source cluster for follow-on requests or changes in behavior.
  2. Review application and reverse-proxy logs around 2026-08-22T19[redacted]38Z–[redacted]43Z for follow-on requests, authentication attempts, uploads, or unexpected successful responses.
  3. Verify that WordPress/PHP components are intended, patched, and minimally exposed; remove unused plugins, themes, administrative routes, and stale PHP files.
  4. Do not infer compromise or isolate the workload solely from this scan. Escalate if later evidence shows successful content retrieval, command output, suspicious process execution, file creation, or novel outbound connectivity.