Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 24, 9:56:42 PM PDT
Evidence through
Aug 24, 9:57:27 PM PDT
AI status
Complete
True positive98% confidence

High-confidence true positive for opportunistic web-shell/path reconnaissance against target privatekind. The incident aggregates 39 requests across 20 PHP/WordPress probe paths in under five seconds, and verified HTTP summaries confirm rapid GET probes from one source cluster with redirect/rejection outcomes (HTTP evidence [redacted] through [redacted]). This establishes the scan, but not compromise: no process or flow evidence is cited by the incident, and HTTP status by itself cannot prove exploit failure.

Attack stage
Reconnaissance / discovery: PHP and WordPress web-shell path enumeration
Model
gpt-5.6-sol · 5 evidence calls

Observed impact

  • Observed impact is limited to a brief burst of inbound reconnaissance requests; the cited HTTP evidence does not establish command execution, persistence, data access, or outbound activity.
  • All 39 requests were characterized by the detector as redirect/rejection outcomes; there is no demonstrated successful web-shell interaction in the available bounded evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

353 observations · 12 http

Explicit uncertainty

  • No process-plane event is cited by this incident, so the available evidence cannot independently determine whether workload process execution occurred during the HTTP burst.
  • No flow-plane event is cited by this incident, so the available evidence cannot independently determine whether temporally related outbound network activity occurred.
  • HTTP status codes and bounded body metadata do not by themselves prove exploit failure; no raw response body or server-generated command output is available here for content-level validation.
  • Source identity is a derived traffic cluster and may represent a proxy, NAT gateway, or multiple workers.
  • Downstream workload affinity is inferred from configured target routing rather than an observed per-request trace edge.

Recommended actions

  1. Retain the HTTP evidence and monitor the source cluster for repeat probes, follow-on exploit requests, authentication attempts, or path-specific response changes.
  2. Review the target's deployed PHP/WordPress files and recent file-integrity telemetry for unexpected web-shell-like artifacts, prioritizing the probed path classes without assuming compromise.
  3. Confirm that unnecessary PHP/WordPress endpoints are absent or inaccessible and keep gateway rejection/rate-limiting controls enabled.
  4. If broader telemetry is available outside this bounded incident, correlate the time window with workload process and egress records; escalate only if execution, file changes, or suspicious outbound activity is observed.