Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 19, 5:50:03 AM PDT
Evidence through
Aug 19, 5:50:16 AM PDT
AI status
Complete
True positive99% confidence

This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.

Attack stage
Reconnaissance / discovery: PHP and WordPress web-shell path enumeration
Model
gpt-5.6-sol · 8 evidence calls

Observed impact

  • The target received 331 rapid web-shell-path probes spanning 167 unique paths [[redacted], [redacted], [redacted], [redacted], 1147abb7-
  • [redacted], [redacted], [redacted], [redacted], [redacted], [redacted], 3ca390a0-48e
  • The observed HTTP consequence was limited to redirects or rejections; no successful exploitation consequence is demonstrated by the available evidence [[redacted], [redacted], 3ca390a0-48e

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

331 observations · 12 http

Explicit uncertainty

  • The source_key is a traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • No process-plane evidence is cited by this incident. Process evidence retrieval using the cited HTTP IDs was unavailable, so correlated execution cannot be evaluated.
  • No flow-plane evidence is cited by this incident. Flow evidence retrieval using the cited HTTP IDs was unavailable, so correlated outbound connections cannot be evaluated.
  • HTTP 301/404 status and redirect/rejection classification do not alone prove that no backend processing occurred; the available evidence establishes no observed success, not definitive exploit failure.
  • Configured target routing does not provide an observed per-request trace edge to a specific downstream workload.

Recommended actions

  1. Keep the incident open for short-term monitoring and alert on recurrence, a change from 301/404 outcomes, or responses containing verified command output.
  2. Apply policy-appropriate rate limiting or temporary blocking to the source cluster if the behavior persists, recognizing that the cluster may aggregate multiple clients.
  3. Confirm that probed PHP/WordPress or web-shell paths are not intentionally deployed and review application/access logs around the incident window for anomalous authenticated actions, uploads, or file changes.
  4. Validate gateway routing and rejection controls for the target; no emergency host isolation is justified solely by the present evidence.