Outbound PHP-initiated HTTP request from compromised WordPress plugin host

Detects outbound HTTP requests where the user-agent starts with 'PHP/' and the URI contains the path for the Admin Menu Editor Pro plugin, suggesting communication between a trojanized WordPress plugin and a remote command-and-control server.