Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 26, 10:36:53 PM PDT
Evidence through
Aug 26, 10:37:25 PM PDT
AI status
Complete
True positive99% confidence

This is a true positive for opportunistic reconnaissance: a rapid burst enumerated PHP and WordPress web-shell-style paths. The available HTTP evidence shows redirects and rejections, so the observed incident is scanning rather than a demonstrated compromise. No cited process or flow evidence was available to establish execution or outbound network consequences.

Attack stage
Reconnaissance / web-shell path discovery
Model
gpt-5.6-sol · 5 evidence calls

Observed impact

  • Confirmed hostile or unauthorized-looking web-path enumeration against the target.
  • No workload execution, persistence, outbound connection, or data-loss consequence is established by the available evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

286 observations · 12 http

Explicit uncertainty

  • No process-plane event is cited by this incident, so the available evidence cannot independently determine whether any workload process executed near the requests.
  • No flow-plane event is cited by this incident, so the available evidence cannot independently assess contemporaneous outbound connections.
  • HTTP status codes alone cannot prove exploit failure; the available summaries do not expose affirmative server-generated command output or another execution indicator.
  • The source key is a traffic cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • Target routing affinity is configured inference rather than an observed per-request workload trace edge.

Recommended actions

  1. Retain and monitor the source cluster for recurrence; apply rate limiting or temporary blocking if consistent with policy and business risk.
  2. Verify that the probed PHP or WordPress paths are not deployed and remove any unexpected scripts or web shells found through normal asset-integrity procedures.
  3. Review application, reverse-proxy, and workload telemetry around 2026-08-27T05[redacted]53Z–[redacted]58Z for request handling, file changes, authentication anomalies, or execution indicators.
  4. Continue process and egress monitoring for the target; escalate only if later evidence shows execution, persistence, suspicious outbound activity, or data access.