Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 27, 1:31:09 PM PDT
Evidence through
Aug 27, 1:31:31 PM PDT
AI status
Complete
True positive98% confidence

This is a true positive for opportunistic reconnaissance/web-shell enumeration, not a confirmed compromise. The detector derived 39 requests across 20 PHP/WordPress probe paths in about 4.8 seconds, and verified HTTP examples are GETs categorized as php_or_wordpress_probe with distinct path hashes [redacted]. The incident records redirect/rejection-only outcomes for all 39 requests. That supports an attempted discovery scan but does not, by HTTP status alone, prove exploit failure. No process or flow evidence references were cited by this incident, so execution, outbound activity, persistence, or other compromise consequences cannot be assessed from the available evidence.

Attack stage
Reconnaissance / discovery of PHP and WordPress web-shell paths
Model
gpt-5.6-sol · 6 evidence calls

Observed impact

  • Observed impact is limited to a rapid inbound path-enumeration burst against the target [redacted].
  • No compromise consequence is demonstrated; redirect/rejection outcomes do not by themselves establish exploit success or failure [redacted].

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

178 observations · 12 http

Explicit uncertainty

  • No process-plane evidence references are cited by this incident; the process-evidence query therefore could not assess execution or workload-side consequences.
  • No flow-plane evidence references are cited by this incident; the flow-evidence query therefore could not assess correlated outbound connections.
  • HTTP status and the derived redirect/rejection outcome do not alone establish exploit failure; no server-generated command output is identified in the available summaries.
  • The source_key is a traffic cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • Downstream workload affinity is inferred from configured target routing and is not an observed per-request trace edge.

Recommended actions

  1. Continue monitoring the source traffic cluster and target for follow-on requests, especially command-bearing requests, uploads, authentication attempts, or successful responses at the probed paths.
  2. Verify that the probed PHP/WordPress and web-shell-like paths do not exist on the target, and review application/origin logs around 2026-08-27T20[redacted]09Z–[redacted]14Z for matching requests or unexpected handlers.
  3. Review workload process and network telemetry for the same interval if available; escalate only if it shows suspicious execution, file creation, or outbound activity.
  4. Apply proportionate rate limiting or blocking to repeated enumeration traffic according to policy, while accounting for the possibility that the source cluster represents shared infrastructure.
  5. Maintain current PHP/WordPress components and remove unused plugins, themes, scripts, and administrative endpoints.