Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 26, 2:49:56 PM PDT
Evidence through
Aug 26, 2:50:23 PM PDT
AI status
Complete
True positive99% confidence

The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The traffic cluster generated a rapid burst that the detector aggregated as 39 requests across 20 PHP/WordPress probe paths from [redacted].438Z through [redacted].271Z. Verified HTTP examples are GET requests categorized as php_or_wordpress_probe and received 301 redirects or 404 rejections; no bounded process or flow evidence is cited to establish execution or follow-on activity. [HTTP: [redacted], [redacted], [redacted], [redacted], [redacted]]

Attack stage
Reconnaissance / web-shell discovery path enumeration
Model
gpt-5.6-sol · 6 evidence calls

Observed impact

  • A brief burst of 39 inbound PHP/WordPress probe requests targeted the service; the incident reports 20 unique probe paths. [HTTP: [redacted] through [redacted]]
  • No successful exploitation or downstream workload consequence is established; the verified HTTP examples show only redirects or rejections. [HTTP: [redacted], [redacted], 701bbc73-cd95-43b
  • [redacted], [redacted]]

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

226 observations · 12 http

Explicit uncertainty

  • No process or flow evidence IDs are cited by this incident. Queries using the cited HTTP IDs were rejected as not cited in those planes, so workload execution and network follow-on cannot be independently assessed from the available evidence.
  • HTTP status alone cannot prove exploit failure. The bounded summaries contain no verified server-generated command output, but exact response bodies are intentionally unavailable.
  • The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • Downstream workload affinity is inferred from configured routing and is not an observed per-request trace edge.

Recommended actions

  1. Retain the existing gateway rejection/redirect controls and monitor for recurrence or changes in method, payload, response behavior, or request rate from the same or related traffic clusters.
  2. Review the target's deployed PHP/WordPress surface and remove or restrict any unnecessary scripts, plugins, upload locations, or administrative endpoints.
  3. If broader telemetry is available outside this bounded incident, review workload process and outbound-flow records around 2026-08-26T21[redacted]56Z–[redacted]02Z for corroboration; do not infer compromise solely from temporal proximity.
  4. Consider rate limiting or temporary source-cluster controls if this probing persists, while accounting for possible proxy or NAT aggregation.