Is it possible it was part of a planned or current exploit chain, some other way it could have been utilized?
It's obvious, basically no one knows what's going on in the _vast_ majority of code running out systems these days. And even if you know 99% the attackers only need to be right once