Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
- Confidence
- 96%
- First seen
- Aug 31, 7:56:22 PM PDT
- Evidence through
- Aug 31, 7:56:55 PM PDT
- AI status
- Complete
The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration against target privatekind. The detector recorded 39 requests across 20 probe paths in roughly 4.3 seconds, and the inspected HTTP evidence confirms repeated GET requests categorized as php_or_wordpress_probe from one derived source cluster [http:[redacted]; http:[redacted]; http:[redacted]; http:[redacted]]. Inspected responses were redirects or 404 rejections; this supports detection of scanning but, because HTTP status alone is not dispositive, does not prove exploit failure. No cited process or flow evidence was available to establish execution or network consequences.
- Attack stage
- Reconnaissance / opportunistic web-shell path enumeration
- Model
- gpt-5.6-sol · 7 evidence calls
Observed impact
- Repeated hostile enumeration traffic reached the HTTP service; sampled probes received 301 redirects or 404 responses [http:[redacted]; http:[redacted]; http:53dccde4-48be-49fb-bcbf-aa90e8
- No command execution, persistence, lateral movement, outbound callback, or data loss is confirmed by the evidence available for this incident.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
303 observations · 12 httpExplicit uncertainty
- No process-plane evidence references are cited by this incident, so the available evidence cannot determine whether any request caused command execution.
- No flow-plane evidence references are cited by this incident, so the available evidence cannot determine whether the activity caused an outbound connection or other network consequence.
- HTTP status codes and body hashes alone do not establish exploit success or failure; response content was not exposed in the bounded summaries.
- The source_key is a derived traffic cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
- Downstream workload affinity is inferred from configured target routing and is not an observed per-request trace edge.
Recommended actions
- Continue monitoring the source cluster and target for follow-on requests, especially any non-rejected response or requests carrying command parameters.
- Review application and gateway logs around 2026-09-01T02[redacted]22Z–[redacted]27Z for backend handling and any evidence of web-shell presence or command output.
- Verify that the enumerated PHP/WordPress paths do not exist and that unnecessary PHP handlers, plugins, themes, and administrative endpoints are removed or patched.
- Apply rate limiting or temporary source-cluster blocking if operationally appropriate, while accounting for possible NAT or proxy aggregation.
- Correlate with endpoint and network telemetry for unexpected child processes or outbound connections near the incident window.