Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 26, 1:54:33 PM PDT
Evidence through
Aug 26, 1:54:40 PM PDT
AI status
Complete
True positive98% confidence

High-confidence true positive for rapid opportunistic PHP/WordPress web-shell path enumeration against target privatekind. Verified HTTP summaries show repeated GET requests categorized as php_or_wordpress_probe, with distinct path hashes, from one derived source cluster over roughly 4.4 seconds. The incident detector reports 38 requests across 20 unique probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone do not prove exploit failure. No process or flow evidence is cited by this incident, so successful execution or follow-on network activity is neither demonstrated nor conclusively excluded.

Attack stage
Reconnaissance / web-shell path discovery
Model
gpt-5.6-sol · 8 evidence calls

Observed impact

  • Confirmed PHP/WordPress web-shell path enumeration reached the HTTP service.
  • No demonstrated command execution, persistence, outbound connection, lateral movement, or data loss in the available cited evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

64 observations · 12 http

Explicit uncertainty

  • No process or flow evidence references are cited by this incident; the corresponding evidence tools could not return lifecycle or conntrack summaries. Execution and follow-on network consequences therefore cannot be independently assessed.
  • HTTP 301/404 status codes do not conclusively establish exploit failure, and raw response bodies are unavailable.
  • The source_key is a traffic cluster, not a proven identity; it may represent a proxy, NAT gateway, or multiple workers.
  • Downstream workload affinity is inferred from configured target routing rather than an observed per-request trace edge.

Recommended actions

  1. Correlate the cited HTTP events with application, reverse-proxy, workload process, and network telemetry for the same time window if available.
  2. Review the target for unexpected PHP files or web shells and verify that unused PHP/WordPress endpoints are absent or inaccessible.
  3. Apply proportionate rate limiting or blocking to repeated probe patterns; do not treat the source cluster as a uniquely identified actor.
  4. Monitor for recurrence, uploads, command-like parameters, unexpected child processes, or novel outbound connections.