Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
- Confidence
- 96%
- First seen
- Aug 19, 5:50:03 AM PDT
- Evidence through
- Aug 19, 5:50:16 AM PDT
- AI status
- Complete
This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.
- Attack stage
- Reconnaissance / discovery: PHP and WordPress web-shell path enumeration
- Model
- gpt-5.6-sol · 8 evidence calls
Observed impact
- The target received 331 rapid web-shell-path probes spanning 167 unique paths [[redacted], [redacted], [redacted], [redacted], 1147abb7-
- [redacted], [redacted], [redacted], [redacted], [redacted], [redacted], 3ca390a0-48e
- The observed HTTP consequence was limited to redirects or rejections; no successful exploitation consequence is demonstrated by the available evidence [[redacted], [redacted], 3ca390a0-48e
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
331 observations · 12 httpExplicit uncertainty
- The source_key is a traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
- No process-plane evidence is cited by this incident. Process evidence retrieval using the cited HTTP IDs was unavailable, so correlated execution cannot be evaluated.
- No flow-plane evidence is cited by this incident. Flow evidence retrieval using the cited HTTP IDs was unavailable, so correlated outbound connections cannot be evaluated.
- HTTP 301/404 status and redirect/rejection classification do not alone prove that no backend processing occurred; the available evidence establishes no observed success, not definitive exploit failure.
- Configured target routing does not provide an observed per-request trace edge to a specific downstream workload.
Recommended actions
- Keep the incident open for short-term monitoring and alert on recurrence, a change from 301/404 outcomes, or responses containing verified command output.
- Apply policy-appropriate rate limiting or temporary blocking to the source cluster if the behavior persists, recognizing that the cluster may aggregate multiple clients.
- Confirm that probed PHP/WordPress or web-shell paths are not intentionally deployed and review application/access logs around the incident window for anomalous authenticated actions, uploads, or file changes.
- Validate gateway routing and rejection controls for the target; no emergency host isolation is justified solely by the present evidence.