Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 31, 7:46:23 PM PDT
Evidence through
Aug 31, 7:46:43 PM PDT
AI status
Complete
True positive98% confidence

This is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The deterministic detector recorded 41 requests against 20 probe paths in roughly 4.7 seconds. The retained HTTP summaries consistently classify the requests as PHP/WordPress probes from one traffic cluster to target privatekind and show only 301 redirects or 404 responses. No cited process or flow evidence is available to establish command execution, persistence, outbound activity, or other compromise consequences.

Attack stage
Reconnaissance / discovery: PHP and WordPress web-shell endpoint enumeration
Model
gpt-5.6-sol · 16 evidence calls

Observed impact

  • The observed activity attempted to discover exposed PHP or WordPress web-shell endpoints.
  • No successful exploitation or adverse workload consequence is demonstrated by the available evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

182 observations · 12 http

Explicit uncertainty

  • The source key denotes a traffic or workload cluster, not a guaranteed individual identity; it may represent a proxy, NAT gateway, or multiple workers.
  • No process evidence identity is cited by this incident, so the available evidence cannot determine whether any temporally related workload process executed.
  • No flow evidence identity is cited by this incident, so the available evidence cannot determine whether any related outbound connection occurred.
  • Configured target routing does not establish an observed per-request trace edge to a particular downstream workload.
  • The bounded HTTP summaries exclude raw response content, so the 404 response bodies cannot be semantically inspected here; HTTP status alone is not proof of exploit failure.

Recommended actions

  1. Continue monitoring the source cluster for follow-on requests that receive materially different responses or correlate with verified process or flow evidence.
  2. Apply policy-appropriate rate limiting or temporary blocking for repeated web-shell enumeration if this traffic is unauthorized.
  3. Verify that PHP and WordPress components, plugins, themes, and upload directories on the routed application are current and do not contain unexpected executable files.
  4. Retain the relevant gateway and workload telemetry and escalate if subsequent evidence shows command output, process execution, file modification, or novel outbound connectivity.